Ãë¾àÁ¡ID |
22633 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¹è³ÊÁ¤º¸¿¡ µû¸£¸é ¿ø°ÝÀÇ À¥ ¼¹ö¿¡´Â OpenSSL 1.0.0n ÀÌÀüÀÇ 1.0.0 ¹öÀüÀÌ ½ÇÇàµÇ°í ÀÖÀ¸¸ç, ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ÀÌÁß ÇØÁ¦ ¿¡·¯°¡ Á¸ÀçÇØ ¼ºñ½º °ÅºÎ°ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3505)
- DTLS Çڵ彦ÀÌÅ© ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇÏ¿© ´Ù·®ÀÇ ¸Þ¸ð¸®¸¦ ¼ÒºñÇÏ°Ô µÇ¾î ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3506)
- Á¶ÀÛµÈ DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ´©¼ö ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3507)
- 'OBJ_obj2txt'¿Í °ü·ÃµÈ ÇÁ¸°Æ® ÇÔ¼ö 'X509_name_*'¿¡¼ ½ºÅÃÁ¤º¸¸¦ ´©¼öÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇØ Á¤º¸À¯ÃâÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3508)
- ¸®ÁÜµÈ ¼¼¼ÇÀ» ó¸®ÇÏ´Â ´ÙÁß ½º·¹µå¿¡¼ 'ec point format extension'À» ´Ù·ê ¶§ ÇØÁ¦µÈ ¸Þ¸ð¸® Write ÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3509)
- Á¶ÀÛµÈ Çîµå½¦ÀÌÅ© ¸Þ½ÃÁö ó¸® °úÁ¤¿¡¼ ÀÓÀÇÀÇ ECDH ¾ÏÈ£È ¼öÆ®¸¦ »ç¿ëÇÒ ¶§ Ŭ¶óÀ̾ðÆ®¿¡ ¼ºñ½º °ÅºÎ °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3510)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: https://www.openssl.org/news/openssl-1.0.0-notes.html https://www.openssl.org/news/secadv_20140806.txt https://www.openssl.org/news/vulnerabilities.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: OpenSSL 1.0.0n ÀÌÀüÀÇ 1.0.0 ¹öÀü Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.0n ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2014-3505,CVE-2014-3506,CVE-2014-3507,CVE-2014-3508,CVE-2014-3509,CVE-2014-3510 (CVE) |
°ü·Ã URL |
69075,69076,69078,69081,69082,69084 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|