English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210300
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ OpenSSL ¹öÀüÀÌ 3.6.1 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼­ 3.6.1 ±Ç°í¹®¿¡¼­ ¾ð±ÞµÈ ¹Ù¿Í °°ÀÌ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- ¹®Á¦ ¿ä¾à: QUIC ÇÁ·ÎÅäÄÝ Å¬¶óÀÌ¾ðÆ® ¶Ç´Â ¼­¹ö¿¡¼­ SSL_CIPHER_find() ÇÔ¼ö¸¦ »ç¿ëÇÏ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ ÇǾî(peer)·ÎºÎÅÍ ¾Ë ¼ö ¾ø´Â ¾ÏÈ£ Á¦Ç°±º(cipher suite)À» ¼ö½ÅÇϸé NULL ¿ªÂüÁ¶°¡ ¹ß»ýÇÕ´Ï´Ù.
¿µÇâ ¿ä¾à: NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶´Â ½ÇÇà ÁßÀÎ ÇÁ·Î¼¼½ºÀÇ ºñÁ¤»óÀûÀÎ Á¾·á¸¦ À¯¹ßÇÏ¿© ¼­ºñ½º °ÅºÎ(Denial of Service)¸¦ ÃÊ·¡ÇÕ´Ï´Ù. ÀϺΠ¾ÖÇø®ÄÉÀ̼ÇÀº ÇǾî·ÎºÎÅÍ ¼ö½ÅÇÑ ¾ÏÈ£ ID¿¡ ´ëÇØ client_hello_cb Äݹ鿡¼­ SSL_CIPHER_find()¸¦ È£ÃâÇÕ´Ï´Ù. QUIC ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÏ´Â SSL °´Ã¼·Î ÀÌ ÀÛ¾÷À» ¼öÇàÇÒ ¶§ °Ë»çµÈ ¾ÏÈ£ ID¸¦ ¾Ë ¼ö ¾ø°Å³ª Áö¿øÇÏÁö ¾Ê´Â °æ¿ì NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶°¡ ¹ß»ýÇÕ´Ï´Ù. QUIC ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡¼­ ÀÌ ÇÔ¼ö¸¦ È£ÃâÇÏ´Â °ÍÀº ¸Å¿ì ÈçÇÑ ÀÏÀÌ ¾Æ´Ï¸ç, ÃÖ¾ÇÀÇ °á°ú°¡ ¼­ºñ½º °ÅºÎ(Denial of Service)À̱⠶§¹®¿¡ ÀÌ ¹®Á¦´Â ½É°¢µµ ³·À½(Low)À¸·Î Æò°¡µÇ¾ú½À´Ï´Ù. Ãë¾àÇÑ ÄÚµå´Â QUIC ÇÁ·ÎÅäÄÝ Áö¿øÀÌ Ãß°¡µÈ 3.2 ¹öÀü¿¡¼­ µµÀԵǾú½À´Ï´Ù. QUIC ±¸ÇöÀÌ OpenSSL FIPS ¸ðµâ °æ°è ¿ÜºÎ¿¡ ÀÖÀ¸¹Ç·Î 3.6, 3.5, 3.4 ¹× 3.3ÀÇ FIPS ¸ðµâÀº ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6, 3.5, 3.4 ¹× 3.3ÀÌ ÀÌ ¹®Á¦¿¡ Ãë¾àÇÕ´Ï´Ù. OpenSSL 3.0, 1.1.1 ¹× 1.0.2´Â ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6.1 ¹öÀü¿¡¼­ ¼öÁ¤µÇ¾ú½À´Ï´Ù. (3.6.0 ¹öÀüºÎÅÍ ¿µÇâÀ» ¹ÞÀ½). (CVE-2025-15468)

- ¹®Á¦ ¿ä¾à: À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀÏÀ» ó¸®Çϸé PKCS12_item_decrypt_d2i_ex() ÇÔ¼ö¿¡¼­ NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
¿µÇâ ¿ä¾à: NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶´Â ÀÛµ¿ Áß´ÜÀ» À¯¹ßÇÏ¿© PKCS#12 ÆÄÀÏÀ» ó¸®ÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡ ¼­ºñ½º °ÅºÎ(Denial of Service)¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. PKCS12_item_decrypt_d2i_ex() ÇÔ¼ö´Â oct ¸Å°³º¯¼ö¸¦ ¿ªÂüÁ¶Çϱâ Àü¿¡ NULLÀÎÁö È®ÀÎÇÏÁö ¾Ê½À´Ï´Ù. À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀϰú ÇÔ²² PKCS12_unpack_p7encdata()¿¡¼­ È£ÃâµÉ ¶§ ÀÌ ¸Å°³º¯¼ö´Â NULLÀÌ µÉ ¼ö ÀÖÀ¸¸ç, ÀÌ·Î ÀÎÇØ ÀÛµ¿ Áß´ÜÀÌ ¹ß»ýÇÕ´Ï´Ù. ÀÌ Ãë¾àÁ¡Àº ¼­ºñ½º °ÅºÎ·Î Á¦ÇѵǸç ÄÚµå ½ÇÇàÀ̳ª ¸Þ¸ð¸® À¯ÃâÀ» ´Þ¼ºÇϱâ À§ÇØ ±ÇÇÑÀ» »ó½Â½Ãų ¼ö ¾ø½À´Ï´Ù. ÀÌ ¹®Á¦¸¦ ¾Ç¿ëÇÏ·Á¸é °ø°ÝÀÚ°¡ À̸¦ ó¸®ÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡ À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀÏÀ» Á¦°øÇØ¾ß ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ÀÌÀ¯·Î ´ç»çÀÇ º¸¾È Á¤Ã¥¿¡ µû¶ó ÀÌ ¹®Á¦´Â ½É°¢µµ ³·À½(Low)À¸·Î Æò°¡µÇ¾ú½À´Ï´Ù. PKCS#12 ±¸ÇöÀÌ OpenSSL FIPS ¸ðµâ °æ°è ¿ÜºÎ¿¡ ÀÖÀ¸¹Ç·Î 3.6, 3.5, 3.4, 3.3 ¹× 3.0ÀÇ FIPS ¸ðµâÀº ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 ¹× 1.0.2°¡ ÀÌ ¹®Á¦¿¡ Ãë¾àÇÕ´Ï´Ù. OpenSSL 3.6.1 ¹öÀü¿¡¼­ ¼öÁ¤µÇ¾ú½À´Ï´Ù. (3.6.0 ¹öÀüºÎÅÍ ¿µÇâÀ» ¹ÞÀ½). (CVE-2025-69421)

* Âü°í »çÀÌÆ®:
https://openssl-library.org/news/secadv/20260127.txt
https://www.cve.org/CVERecord?id=CVE-2025-11187
https://www.cve.org/CVERecord?id=CVE-2025-15467
https://www.cve.org/CVERecord?id=CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15469
https://www.cve.org/CVERecord?id=CVE-2025-66199
https://www.cve.org/CVERecord?id=CVE-2025-68160
https://www.cve.org/CVERecord?id=CVE-2025-69418
https://www.cve.org/CVERecord?id=CVE-2025-69419
https://www.cve.org/CVERecord?id=CVE-2025-69420
https://www.cve.org/CVERecord?id=CVE-2025-69421
https://www.cve.org/CVERecord?id=CVE-2026-22795
https://www.cve.org/CVERecord?id=CVE-2026-22796

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
3.6.1 ÀÌÀüÀÇ OpenSSL 3.6.x ¹öÀüµé
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽйöÀü(3.6.1 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2025-11187,CVE-2025-15467,CVE-2025-15468,CVE-2025-15469,CVE-2025-66199,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)