| Ãë¾àÁ¡ID |
210300 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ OpenSSL ¹öÀüÀÌ 3.6.1 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼ 3.6.1 ±Ç°í¹®¿¡¼ ¾ð±ÞµÈ ¹Ù¿Í °°ÀÌ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- ¹®Á¦ ¿ä¾à: QUIC ÇÁ·ÎÅäÄÝ Å¬¶óÀÌ¾ðÆ® ¶Ç´Â ¼¹ö¿¡¼ SSL_CIPHER_find() ÇÔ¼ö¸¦ »ç¿ëÇÏ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ ÇǾî(peer)·ÎºÎÅÍ ¾Ë ¼ö ¾ø´Â ¾ÏÈ£ Á¦Ç°±º(cipher suite)À» ¼ö½ÅÇϸé NULL ¿ªÂüÁ¶°¡ ¹ß»ýÇÕ´Ï´Ù. ¿µÇâ ¿ä¾à: NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶´Â ½ÇÇà ÁßÀÎ ÇÁ·Î¼¼½ºÀÇ ºñÁ¤»óÀûÀÎ Á¾·á¸¦ À¯¹ßÇÏ¿© ¼ºñ½º °ÅºÎ(Denial of Service)¸¦ ÃÊ·¡ÇÕ´Ï´Ù. ÀϺΠ¾ÖÇø®ÄÉÀ̼ÇÀº ÇǾî·ÎºÎÅÍ ¼ö½ÅÇÑ ¾ÏÈ£ ID¿¡ ´ëÇØ client_hello_cb Äݹ鿡¼ SSL_CIPHER_find()¸¦ È£ÃâÇÕ´Ï´Ù. QUIC ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÏ´Â SSL °´Ã¼·Î ÀÌ ÀÛ¾÷À» ¼öÇàÇÒ ¶§ °Ë»çµÈ ¾ÏÈ£ ID¸¦ ¾Ë ¼ö ¾ø°Å³ª Áö¿øÇÏÁö ¾Ê´Â °æ¿ì NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶°¡ ¹ß»ýÇÕ´Ï´Ù. QUIC ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡¼ ÀÌ ÇÔ¼ö¸¦ È£ÃâÇÏ´Â °ÍÀº ¸Å¿ì ÈçÇÑ ÀÏÀÌ ¾Æ´Ï¸ç, ÃÖ¾ÇÀÇ °á°ú°¡ ¼ºñ½º °ÅºÎ(Denial of Service)À̱⠶§¹®¿¡ ÀÌ ¹®Á¦´Â ½É°¢µµ ³·À½(Low)À¸·Î Æò°¡µÇ¾ú½À´Ï´Ù. Ãë¾àÇÑ ÄÚµå´Â QUIC ÇÁ·ÎÅäÄÝ Áö¿øÀÌ Ãß°¡µÈ 3.2 ¹öÀü¿¡¼ µµÀԵǾú½À´Ï´Ù. QUIC ±¸ÇöÀÌ OpenSSL FIPS ¸ðµâ °æ°è ¿ÜºÎ¿¡ ÀÖÀ¸¹Ç·Î 3.6, 3.5, 3.4 ¹× 3.3ÀÇ FIPS ¸ðµâÀº ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6, 3.5, 3.4 ¹× 3.3ÀÌ ÀÌ ¹®Á¦¿¡ Ãë¾àÇÕ´Ï´Ù. OpenSSL 3.0, 1.1.1 ¹× 1.0.2´Â ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6.1 ¹öÀü¿¡¼ ¼öÁ¤µÇ¾ú½À´Ï´Ù. (3.6.0 ¹öÀüºÎÅÍ ¿µÇâÀ» ¹ÞÀ½). (CVE-2025-15468)
- ¹®Á¦ ¿ä¾à: À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀÏÀ» ó¸®Çϸé PKCS12_item_decrypt_d2i_ex() ÇÔ¼ö¿¡¼ NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿µÇâ ¿ä¾à: NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶´Â ÀÛµ¿ Áß´ÜÀ» À¯¹ßÇÏ¿© PKCS#12 ÆÄÀÏÀ» ó¸®ÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡ ¼ºñ½º °ÅºÎ(Denial of Service)¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. PKCS12_item_decrypt_d2i_ex() ÇÔ¼ö´Â oct ¸Å°³º¯¼ö¸¦ ¿ªÂüÁ¶Çϱâ Àü¿¡ NULLÀÎÁö È®ÀÎÇÏÁö ¾Ê½À´Ï´Ù. À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀϰú ÇÔ²² PKCS12_unpack_p7encdata()¿¡¼ È£ÃâµÉ ¶§ ÀÌ ¸Å°³º¯¼ö´Â NULLÀÌ µÉ ¼ö ÀÖÀ¸¸ç, ÀÌ·Î ÀÎÇØ ÀÛµ¿ Áß´ÜÀÌ ¹ß»ýÇÕ´Ï´Ù. ÀÌ Ãë¾àÁ¡Àº ¼ºñ½º °ÅºÎ·Î Á¦ÇѵǸç ÄÚµå ½ÇÇàÀ̳ª ¸Þ¸ð¸® À¯ÃâÀ» ´Þ¼ºÇϱâ À§ÇØ ±ÇÇÑÀ» »ó½Â½Ãų ¼ö ¾ø½À´Ï´Ù. ÀÌ ¹®Á¦¸¦ ¾Ç¿ëÇÏ·Á¸é °ø°ÝÀÚ°¡ À̸¦ ó¸®ÇÏ´Â ¾ÖÇø®ÄÉÀ̼ǿ¡ À߸øµÈ Çü½ÄÀÇ PKCS#12 ÆÄÀÏÀ» Á¦°øÇØ¾ß ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ÀÌÀ¯·Î ´ç»çÀÇ º¸¾È Á¤Ã¥¿¡ µû¶ó ÀÌ ¹®Á¦´Â ½É°¢µµ ³·À½(Low)À¸·Î Æò°¡µÇ¾ú½À´Ï´Ù. PKCS#12 ±¸ÇöÀÌ OpenSSL FIPS ¸ðµâ °æ°è ¿ÜºÎ¿¡ ÀÖÀ¸¹Ç·Î 3.6, 3.5, 3.4, 3.3 ¹× 3.0ÀÇ FIPS ¸ðµâÀº ÀÌ ¹®Á¦ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 ¹× 1.0.2°¡ ÀÌ ¹®Á¦¿¡ Ãë¾àÇÕ´Ï´Ù. OpenSSL 3.6.1 ¹öÀü¿¡¼ ¼öÁ¤µÇ¾ú½À´Ï´Ù. (3.6.0 ¹öÀüºÎÅÍ ¿µÇâÀ» ¹ÞÀ½). (CVE-2025-69421)
* Âü°í »çÀÌÆ®: https://openssl-library.org/news/secadv/20260127.txt https://www.cve.org/CVERecord?id=CVE-2025-11187 https://www.cve.org/CVERecord?id=CVE-2025-15467 https://www.cve.org/CVERecord?id=CVE-2025-15468 https://www.cve.org/CVERecord?id=CVE-2025-15469 https://www.cve.org/CVERecord?id=CVE-2025-66199 https://www.cve.org/CVERecord?id=CVE-2025-68160 https://www.cve.org/CVERecord?id=CVE-2025-69418 https://www.cve.org/CVERecord?id=CVE-2025-69419 https://www.cve.org/CVERecord?id=CVE-2025-69420 https://www.cve.org/CVERecord?id=CVE-2025-69421 https://www.cve.org/CVERecord?id=CVE-2026-22795 https://www.cve.org/CVERecord?id=CVE-2026-22796
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: 3.6.1 ÀÌÀüÀÇ OpenSSL 3.6.x ¹öÀüµé Linux Any version Unix Any version Microsoft Windows Any version |
| ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽйöÀü(3.6.1 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2025-11187,CVE-2025-15467,CVE-2025-15468,CVE-2025-15469,CVE-2025-66199,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|