English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22713
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¹è³Ê Á¤º¸¿¡ ÀÇÇÏ¸é ¿ø°Ý È£½ºÆ®¿¡ OpenSSL 1.0.2g ÀÌÀüÀÇ 1.0.2 ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç ´ÙÀ½ÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- ÀÎÅÚ »÷µåºê¸´Áö ¸¶ÀÌÅ©·Î ¾ÆÅ°ÅØó¿¡¼­ À߸øµÈ Á¶ÀÛÀ» ÇÒ ¶§ cash-bank Ãæµ¹·Î ÀÎÇÏ¿© Å° Á¤º¸°¡ ³ëÃâµÉ ¼ö ÀÖ´Ù. (CVE-2016-0702)

- »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ Á¶ÀÛµÈ DSA °³ÀÎÅ°¸¦ ÆĽÌÇÒ¶§ ÀÌÁß ÇØÁ¦ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¸Þ¸ð¸® ºØ±«°¡ ¹ß»ýÇÏ¸ç ¼­ºñ½º °ÅºÎ»óÅ¿¡ ºüÁö°Å³ª ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2016-0705)

- BN_hex2bn(), BN_dec2bn() ÇÔ¼ö¿¡ ³Î Æ÷ÀÎÅÍ ÂüÁ¶ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ¿ø°Ý °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇØ Èü ºØ±«¸¦ ¹ß»ý½Ãų ¼ö ÀÖÀ¸¸ç ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0797)

- À¯È¿ÇÏÁö ¾ÊÀº »ç¿ëÀÚ À̸§À» ´Ù·ê ¶§ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°Ý °ø°ÝÀÚ´Â Á¶ÀÛµÈ »ç¿ëÀÚ À̸§À¸·Î Ä¿³Ø¼Ç¸¶´Ù 300byte ¸Þ¸ð¸® ´©¼ö¸¦ ¹ß»ý½ÃÄÑ ¸Þ¸ð¸® °í°¥ »óÅ¿¡ ºüÁö°Ô ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0798)

- ´ÙÁß ¸Þ¸ð¸® ºØ±« Ãë¾àÁ¡ÀÌ Á¸ÀçÇØ ¼­ºñ½º °ÅºÎ »óÅ¿¡ ºüÁö°Å³ª ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2016-0799)

- DROWN (Decrypting RSA with Obsolete and Weakened eNcryption) À̶ó°í ¾Ë·ÁÁø Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº Sockets Layer Version 2 (SSLv2) ±¸Çö¿¡ °áÇÔÀÌ Á¸ÀçÇØ ¹ß»ýÇϸç TLS ÆÐŶÀÇ ¾ÏÈ£¸¦ Çص¶ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0800)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.openssl.org/news/secadv/20160301.txt
https://www.openssl.org/news/cl102.txt
https://drownattack.com/
https://www.drownattack.com/drown-attack-paper.pdf

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
1.0.2g ÀÌÀüÀÇ OpenSSL 1.0.2
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.2g ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2016-0702,CVE-2016-0705,CVE-2016-0797,CVE-2016-0798,CVE-2016-0799,CVE-2016-0800 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)