Ãë¾àÁ¡ID |
210226 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ OpenSSL ¹öÀüÀÌ 3.0.6 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼ 3.0.6 ±Ç°í»çÇ׿¡ ¾ð±ÞµÈ Ãë¾à¼ºÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- OpenSSLÀº °ú°Å EVP_CIIPER_meth_new() ÇÔ¼ö¿Í °ü·Ã ÇÔ¼ö È£ÃâÀ» ÅëÇÑ »ç¿ëÀÚ ÁöÁ¤ ¾ÏÈ£ »ý¼ºÀ» Áö¿øÇÕ´Ï´Ù.ÀÌ ±â´ÉÀº OpenSSL 3.0¿¡¼ ´õ ÀÌ»ó »ç¿ëµÇÁö ¾ÊÀ¸¸ç ¾ÖÇø®ÄÉÀÌ¼Ç ÀÛ¼ºÀÚ´Â »ç¿ëÀÚ ÁöÁ¤ ¾ÏÈ£¸¦ ±¸ÇöÇϱâ À§ÇØ »õ·Î¿î °ø±ÞÀÚ ¸ÞÄ¿´ÏÁòÀ» »ç¿ëÇϵµ·Ï ±ÇÀåµË´Ï´Ù.OpenSSL ¹öÀü 3.0.0 ~ 3.0.5¿¡¼ EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2() ÇÔ¼ö(À¯»çÇÑ À̸§ÀÇ ´Ù¸¥ ¾ÏÈ£È ÇÔ¼ö ¹× ¾ÏÈ£ Çص¶ ÃʱâÈ ÇÔ¼ö)¿¡ Àü´ÞµÈ »ç¿ëÀÚ ÁöÁ¤ ¾ÏÈ£¸¦ À߸ø ó¸®ÇÕ´Ï´Ù.»ç¿ëÀÚ ÁöÁ¤ ¾ÏÈ£¸¦ Á÷Á¢ »ç¿ëÇÏ´Â ´ë½Å »ç¿ë °¡´ÉÇÑ °ø±ÞÀڷκÎÅÍ µ¿µîÇÑ ¾ÏÈ£¸¦ À߸ø °¡Á®¿À·Á°í ½ÃµµÇÕ´Ï´Ù. EVP_CIPHER_meth_new()¿¡ Àü´ÞµÈ NID¸¦ ±â¹ÝÀ¸·Î µ¿µîÇÑ ¾ÏÈ£¸¦ ã½À´Ï´Ù. ÀÌ NID´Â ÁÖ¾îÁø ¾ÏÈ£¿¡ ´ëÇÑ °íÀ¯ÇÑ NID¸¦ ³ªÅ¸³»¾ß ÇÕ´Ï´Ù.±×·¯³ª ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ EVP_CIPHER_meth_new() È£Ãâ¿¡¼ NID_undef¸¦ ÀÌ °ªÀ¸·Î À߸ø Àü´ÞÇÒ ¼ö ÀÖ½À´Ï´Ù. NID_undef°¡ ÀÌ·¯ÇÑ ¹æ½ÄÀ¸·Î »ç¿ëµÇ¸é OpenSSL ¾ÏÈ£È/º¹È£È ÃʱâÈ ±â´ÉÀº NULL ¾ÏÈ£¸¦ µ¿µîÇÏ°Ô ÀÏÄ¡½ÃÅ°°í »ç¿ë °¡´ÉÇÑ °ø±ÞÀڷκÎÅÍ À̸¦ °¡Á®¿É´Ï´Ù. ±âº» °ø±ÞÀÚ°¡ ·ÎµåµÈ °æ¿ì(¶Ç´Â ÀÌ ¾ÏÈ£¸¦ Á¦°øÇϴ Ÿ»ç °ø±ÞÀÚ°¡ ·ÎµåµÈ °æ¿ì) ¼º°øÇÕ´Ï´Ù. NULL ¾ÏÈ£¸¦ »ç¿ëÇÑ´Ù´Â °ÍÀº Æò¹®ÀÌ ¾ÏÈ£¹®À¸·Î ¹æÃâµÈ´Ù´Â °ÍÀ» ÀǹÌÇÕ´Ï´Ù. ÀÀ¿ë ÇÁ·Î±×·¥Àº NID_undef¸¦ »ç¿ëÇÏ¿© EVP_CIPHER_meth_new()¸¦ È£ÃâÇÏ°í ÀÌÈÄ¿¡ ¾ÏÈ£È/¾ÏÈ£ Çص¶ ÃʱâÈ ±â´É¿¡ ´ëÇÑ È£Ãâ¿¡¼ À̸¦ »ç¿ëÇÏ´Â °æ¿ì¿¡¸¸ ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù. SSL/TLS¸¸ »ç¿ëÇÏ´Â ÀÀ¿ë ÇÁ·Î±×·¥Àº ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.0.6¿¡¼ ¼öÁ¤µÇ¾ú½À´Ï´Ù(3.0.0-3.0.5¿¡ ¿µÇâÀ» ¹ÞÀ½). (CVE-2022-3358)
* Âü°í »çÀÌÆ®: https://cve.org/CVERecord?id=CVE-2022-3358 http://www.nessus.org/u?8748528d https://www.openssl.org/news/secadv/20221011.txt
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: 3.0.6 ÀÌÀüÀÇ OpenSSL 3.0.x ¹öÀüµé Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(3.0.6 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2022-3358 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|