English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22633
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¹è³ÊÁ¤º¸¿¡ µû¸£¸é ¿ø°ÝÀÇ À¥ ¼­¹ö¿¡´Â OpenSSL 1.0.0n ÀÌÀüÀÇ 1.0.0 ¹öÀüÀÌ ½ÇÇàµÇ°í ÀÖÀ¸¸ç, ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ÀÌÁß ÇØÁ¦ ¿¡·¯°¡ Á¸ÀçÇØ ¼­ºñ½º °ÅºÎ°ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3505)

- DTLS Çڵ彦ÀÌÅ© ¸Þ½ÃÁö¸¦ ´Ù·ê ¶§ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇÏ¿© ´Ù·®ÀÇ ¸Þ¸ð¸®¸¦ ¼ÒºñÇÏ°Ô µÇ¾î ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2014-3506)

- Á¶ÀÛµÈ DTLS ÆÐŶÀ» ´Ù·ê ¶§ ¸Þ¸ð¸® ´©¼ö ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3507)

- 'OBJ_obj2txt'¿Í °ü·ÃµÈ ÇÁ¸°Æ® ÇÔ¼ö 'X509_name_*'¿¡¼­ ½ºÅÃÁ¤º¸¸¦ ´©¼öÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇØ Á¤º¸À¯ÃâÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3508)

- ¸®ÁÜµÈ ¼¼¼ÇÀ» ó¸®ÇÏ´Â ´ÙÁß ½º·¹µå¿¡¼­ 'ec point format extension'À» ´Ù·ê ¶§ ÇØÁ¦µÈ ¸Þ¸ð¸® Write ÇÏ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2014-3509)

- Á¶ÀÛµÈ Çîµå½¦ÀÌÅ© ¸Þ½ÃÁö ó¸® °úÁ¤¿¡¼­ ÀÓÀÇÀÇ ECDH ¾Ïȣȭ ¼öÆ®¸¦ »ç¿ëÇÒ ¶§ Ŭ¶óÀ̾ðÆ®¿¡ ¼­ºñ½º °ÅºÎ °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3510)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.openssl.org/news/openssl-1.0.0-notes.html
https://www.openssl.org/news/secadv_20140806.txt
https://www.openssl.org/news/vulnerabilities.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenSSL 1.0.0n ÀÌÀüÀÇ 1.0.0 ¹öÀü
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.0n ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2014-3505,CVE-2014-3506,CVE-2014-3507,CVE-2014-3508,CVE-2014-3509,CVE-2014-3510 (CVE)
°ü·Ã URL 69075,69076,69078,69081,69082,69084 (SecurityFocus)
°ü·Ã URL (ISS)