English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22483
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â SSL°ú °ü·ÃµÈ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç À¥ ¼­¹ö¿¡´Â 0.9.8n ÀÌÀüÀÇ OpenSSLÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÇØ´ç ¹öÀüµéÀº ´ÙÀ½°ú °°Àº Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- kerberos ¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤µÈ ¹öÀü¿¡¼­ , kerberos ¼³Á¤È­ÀÏÀ» ÀÐÀ»¼ö ¾øÀ»¶§ ¸®ÅÏ°ªÀ» üũÇÏÁö ¾Ê¾Æ crash µÉ¼öÀÖ´Ù.

- TLS ¿¬°á¿¡¼­ À߸øµÈ ·¹ÄÚµå Æ÷¸äÀÌ OpenSSL ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®¸¦ Å©·¡½¬ ½Ãų¼öÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.openssl.org/news/secadv_20100324.txt
http://marc.info/?l=openssl-announce&m=126945948000371&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenSSL Project OpenSSL 0.9.8n ÀÌÀü ¹öÀü
ÇØ°áÃ¥ OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(0.9.8n ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2010-0433,CVE-2010-0740 (CVE)
°ü·Ã URL 39013 (SecurityFocus)
°ü·Ã URL (ISS)