Ãë¾àÁ¡ID |
22713 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¹è³Ê Á¤º¸¿¡ ÀÇÇÏ¸é ¿ø°Ý È£½ºÆ®¿¡ OpenSSL 1.0.2g ÀÌÀüÀÇ 1.0.2 ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç ´ÙÀ½ÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- ÀÎÅÚ »÷µåºê¸´Áö ¸¶ÀÌÅ©·Î ¾ÆÅ°ÅØó¿¡¼ À߸øµÈ Á¶ÀÛÀ» ÇÒ ¶§ cash-bank Ãæµ¹·Î ÀÎÇÏ¿© Å° Á¤º¸°¡ ³ëÃâµÉ ¼ö ÀÖ´Ù. (CVE-2016-0702)
- »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ Á¶ÀÛµÈ DSA °³ÀÎÅ°¸¦ ÆĽÌÇÒ¶§ ÀÌÁß ÇØÁ¦ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¸Þ¸ð¸® ºØ±«°¡ ¹ß»ýÇÏ¸ç ¼ºñ½º °ÅºÎ»óÅ¿¡ ºüÁö°Å³ª ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2016-0705)
- BN_hex2bn(), BN_dec2bn() ÇÔ¼ö¿¡ ³Î Æ÷ÀÎÅÍ ÂüÁ¶ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ¿ø°Ý °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇØ Èü ºØ±«¸¦ ¹ß»ý½Ãų ¼ö ÀÖÀ¸¸ç ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0797)
- À¯È¿ÇÏÁö ¾ÊÀº »ç¿ëÀÚ À̸§À» ´Ù·ê ¶§ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°Ý °ø°ÝÀÚ´Â Á¶ÀÛµÈ »ç¿ëÀÚ À̸§À¸·Î Ä¿³Ø¼Ç¸¶´Ù 300byte ¸Þ¸ð¸® ´©¼ö¸¦ ¹ß»ý½ÃÄÑ ¸Þ¸ð¸® °í°¥ »óÅ¿¡ ºüÁö°Ô ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0798)
- ´ÙÁß ¸Þ¸ð¸® ºØ±« Ãë¾àÁ¡ÀÌ Á¸ÀçÇØ ¼ºñ½º °ÅºÎ »óÅ¿¡ ºüÁö°Å³ª ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2016-0799)
- DROWN (Decrypting RSA with Obsolete and Weakened eNcryption) À̶ó°í ¾Ë·ÁÁø Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº Sockets Layer Version 2 (SSLv2) ±¸Çö¿¡ °áÇÔÀÌ Á¸ÀçÇØ ¹ß»ýÇϸç TLS ÆÐŶÀÇ ¾ÏÈ£¸¦ Çص¶ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-0800)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: https://www.openssl.org/news/secadv/20160301.txt https://www.openssl.org/news/cl102.txt https://drownattack.com/ https://www.drownattack.com/drown-attack-paper.pdf
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: 1.0.2g ÀÌÀüÀÇ OpenSSL 1.0.2 Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.2g ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2016-0702,CVE-2016-0705,CVE-2016-0797,CVE-2016-0798,CVE-2016-0799,CVE-2016-0800 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|