English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22632
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¹è³ÊÁ¤º¸¿¡ µû¸£¸é ¿ø°ÝÀÇ À¥ ¼­¹ö¿¡´Â OpenSSL 1.0.1i ÀÌÀüÀÇ 1.0.1 ¹öÀüÀÌ ½ÇÇàµÇ°í ÀÖÀ¸¸ç, ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ÀÌÁß ÇØÁ¦ ¿¡·¯°¡ Á¸ÀçÇØ ¼­ºñ½º °ÅºÎ°ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3505)

- DTLS Çڵ彦ÀÌÅ© ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇÏ¿© ´Ù·®ÀÇ ¸Þ¸ð¸®¸¦ ¼ÒºñÇÏ°Ô µÇ¾î ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3506)

- Á¶ÀÛµÈ DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ´©¼ö ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3507)

- 'OBJ_obj2txt'¿Í °ü·ÃµÈ ÇÁ¸°Æ® ÇÔ¼ö 'X509_name_*'¿¡¼­ ½ºÅÃÁ¤º¸¸¦ ´©¼öÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇØ Á¤º¸À¯ÃâÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3508)

- ¸®ÁÜµÈ ¼¼¼ÇÀ» ó¸®ÇÏ´Â ´ÙÁß ½º·¹µå¿¡¼­ 'ec point format extension'À» ´Ù·ê ¶§ ÇØÁ¦µÈ ¸Þ¸ð¸® Write ÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3509)

- Á¶ÀÛµÈ Çîµå½¦ÀÌÅ© ¸Þ½ÃÁö ó¸® °úÁ¤¿¡¼­ ÀÓÀÇÀÇ ECDH ¾Ïȣȭ ¼öÆ®¸¦ »ç¿ëÇÒ ¶§ Ŭ¶óÀ̾ðÆ®¿¡ ¼­ºñ½º °ÅºÎ °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3510)

- ºÐÇÒµÈ 'ClientHello' ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®°£ ³ôÀº ¾Ïȣȭ ÇÁ·ÎÅäÄÝÀÌ »ç¿ë °¡´ÉÇÏ°Ô µÊ¿¡µµ ºÒ±¸ÇÏ°í TLS 1.0ÀÌ °­Á¦·Î »ç¿ëÇÏ°Ô µÇ¾î man-in-the-middle °ø°ÝÀÌ °¡´ÉÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3511)

- Secure Remote Password protocol (SRP) ÆĶó¹ÌÅ͸¦ ´Ù·ê ¶§ ¹öÆÛ¿À¹öÇÃ·Î¿ì ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3512)

- Secure Remote Password protocol (SRP)À» ´Ù·ê ¶§ ³Î Æ÷ÀÎÅÍ ÂüÁ¶ ¿¡·¯°¡ ¹ß»ýÇØ Å¬¶óÀ̾ðÆ®°¡ Å©·¡½¬ µÇ´Â ¼­ºñ½º °ÅºÎ»óÅ¿¡ ºüÁú ¼ö ÀÖ´Ù. (CVE-2014-5139)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.openssl.org/news/openssl-1.0.1-notes.html
https://www.openssl.org/news/secadv_20140806.txt
https://www.openssl.org/news/vulnerabilities.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenSSL 1.0.1i ÀÌÀüÀÇ 1.0.1 ¹öÀü
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.1i ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2014-3505,CVE-2014-3506,CVE-2014-3507,CVE-2014-3508,CVE-2014-3509,CVE-2014-3510,CVE-2014-3511,CVE-2014-3512,CVE-2014-5139 (CVE)
°ü·Ã URL 69075,69076,69077,69078,69079,69081,69082,69083,69084 (SecurityFocus)
°ü·Ã URL (ISS)