Ãë¾àÁ¡ID |
22632 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¹è³ÊÁ¤º¸¿¡ µû¸£¸é ¿ø°ÝÀÇ À¥ ¼¹ö¿¡´Â OpenSSL 1.0.1i ÀÌÀüÀÇ 1.0.1 ¹öÀüÀÌ ½ÇÇàµÇ°í ÀÖÀ¸¸ç, ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ÀÌÁß ÇØÁ¦ ¿¡·¯°¡ Á¸ÀçÇØ ¼ºñ½º °ÅºÎ°ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3505)
- DTLS Çڵ彦ÀÌÅ© ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇÏ¿© ´Ù·®ÀÇ ¸Þ¸ð¸®¸¦ ¼ÒºñÇÏ°Ô µÇ¾î ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3506)
- Á¶ÀÛµÈ DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ´©¼ö ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3507)
- 'OBJ_obj2txt'¿Í °ü·ÃµÈ ÇÁ¸°Æ® ÇÔ¼ö 'X509_name_*'¿¡¼ ½ºÅÃÁ¤º¸¸¦ ´©¼öÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇØ Á¤º¸À¯ÃâÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3508)
- ¸®ÁÜµÈ ¼¼¼ÇÀ» ó¸®ÇÏ´Â ´ÙÁß ½º·¹µå¿¡¼ 'ec point format extension'À» ´Ù·ê ¶§ ÇØÁ¦µÈ ¸Þ¸ð¸® Write ÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3509)
- Á¶ÀÛµÈ Çîµå½¦ÀÌÅ© ¸Þ½ÃÁö ó¸® °úÁ¤¿¡¼ ÀÓÀÇÀÇ ECDH ¾ÏÈ£È ¼öÆ®¸¦ »ç¿ëÇÒ ¶§ Ŭ¶óÀ̾ðÆ®¿¡ ¼ºñ½º °ÅºÎ °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3510)
- ºÐÇÒµÈ 'ClientHello' ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ ¼¹ö¿Í Ŭ¶óÀ̾ðÆ®°£ ³ôÀº ¾ÏÈ£È ÇÁ·ÎÅäÄÝÀÌ »ç¿ë °¡´ÉÇÏ°Ô µÊ¿¡µµ ºÒ±¸ÇÏ°í TLS 1.0ÀÌ °Á¦·Î »ç¿ëÇÏ°Ô µÇ¾î man-in-the-middle °ø°ÝÀÌ °¡´ÉÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3511)
- Secure Remote Password protocol (SRP) ÆĶó¹ÌÅ͸¦ ´Ù·ê ¶§ ¹öÆÛ¿À¹öÇÃ·Î¿ì ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3512)
- Secure Remote Password protocol (SRP)À» ´Ù·ê ¶§ ³Î Æ÷ÀÎÅÍ ÂüÁ¶ ¿¡·¯°¡ ¹ß»ýÇØ Å¬¶óÀ̾ðÆ®°¡ Å©·¡½¬ µÇ´Â ¼ºñ½º °ÅºÎ»óÅ¿¡ ºüÁú ¼ö ÀÖ´Ù. (CVE-2014-5139)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: https://www.openssl.org/news/openssl-1.0.1-notes.html https://www.openssl.org/news/secadv_20140806.txt https://www.openssl.org/news/vulnerabilities.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: OpenSSL 1.0.1i ÀÌÀüÀÇ 1.0.1 ¹öÀü Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.1i ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2014-3505,CVE-2014-3506,CVE-2014-3507,CVE-2014-3508,CVE-2014-3509,CVE-2014-3510,CVE-2014-3511,CVE-2014-3512,CVE-2014-5139 (CVE) |
°ü·Ã URL |
69075,69076,69077,69078,69079,69081,69082,69083,69084 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|