English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22982
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ OpenSSL ¹öÀüÀº 1.0.2za ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼­ 1.0.2za ±Ç°í¿¡ ¾ð±ÞµÈ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- ASN.1 ¹®ÀÚ¿­Àº ¹®ÀÚ¿­ µ¥ÀÌÅ͸¦ º¸À¯ÇÏ´Â ¹öÆÛ¿Í ¹öÆÛ ±æÀ̸¦ º¸À¯ÇÏ´Â Çʵ带 Æ÷ÇÔÇÏ´Â ASN1_STRING ±¸Á¶·Î OpenSSL ³»¿¡¼­ ³»ºÎÀûÀ¸·Î Ç¥ÇöµË´Ï´Ù. ÀÌ°ÍÀº NUL(0) ¹ÙÀÌÆ®·Î ³¡³ª´Â ¹®ÀÚ¿­ µ¥ÀÌÅÍ¿¡ ´ëÇÑ ¹öÆÛ·Î ´Ù½Ã ³ªÅ¸³ª´Â ÀÏ¹Ý C ¹®ÀÚ¿­°ú ´ëÁ¶µË´Ï´Ù. ¾ö°ÝÇÑ ¿ä±¸ »çÇ×Àº ¾Æ´ÏÁö¸¸ OpenSSLÀÇ ÀÚü d2i ÇÔ¼ö(¹× ±âŸ À¯»çÇÑ ±¸¹® ºÐ¼® ±â´É)¸¦ »ç¿ëÇÏ¿© ±¸¹® ºÐ¼®µÇ´Â ASN.1 ¹®ÀÚ¿­°ú ASN1_STRING_set() ÇÔ¼ö·Î °ªÀÌ ¼³Á¤µÈ ¹®ÀÚ¿­Àº Ãß°¡·Î NUL¿¡¼­ ¹ÙÀÌÆ® ¹è¿­À» Á¾·áÇÕ´Ï´Ù. ASN1_STRING ±¸Á¶. ±×·¯³ª ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ASN1_STRING ¹è¿­¿¡¼­ µ¥ÀÌÅÍ ¹× ±æÀÌ Çʵ带 Á÷Á¢ ¼³Á¤ÇÏ¿© ¹ÙÀÌÆ® ¹è¿­À» NUL Á¾·áÇÏÁö ¾Ê´Â À¯È¿ÇÑ ASN1_STRING ±¸Á¶¸¦ Á÷Á¢ ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ASN1_STRING_set0() ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© ¹ß»ýÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ASN.1 µ¥ÀÌÅ͸¦ ÀμâÇÏ´Â ¼ö¸¹Àº OpenSSL ÇÔ¼ö´Â ASN1_STRING ¹ÙÀÌÆ® ¹è¿­ÀÌ NUL Á¾·áµÉ °ÍÀ̶ó°í °¡Á¤ÇÏ´Â °ÍÀ¸·Î ³ªÅ¸³µ½À´Ï´Ù. ºñ·Ï ÀÌ°ÍÀÌ Á÷Á¢ ±¸¼ºµÈ ¹®ÀÚ¿­¿¡ ´ëÇØ º¸ÀåµÇÁö´Â ¾ÊÁö¸¸. ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ÀμâÇÒ ASN.1 ±¸Á¶¸¦ ¿äûÇÏ°í ÇØ´ç ASN.1 ±¸Á¶°¡ µ¥ÀÌÅÍ Çʵ带 Á¾·áÇÏ´Â NUL ¾øÀÌ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ÀÇÇØ Á÷Á¢ ±¸¼ºµÈ ASN1_STRINGÀ» Æ÷ÇÔÇÏ´Â °æ¿ì Àб⠹öÆÛ ¿À¹ö·±ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÎÁõ¼­ÀÇ À̸§ Á¦¾à ó¸® Áß¿¡µµ µ¿ÀÏÇÑ ÀÏÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù(¿¹: ÀÎÁõ¼­°¡ OpenSSL ±¸¹® ºÐ¼® ±â´ÉÀ» ÅëÇØ ·ÎµåÇÏ´Â ´ë½Å ¾ÖÇø®ÄÉÀ̼ǿ¡ ÀÇÇØ Á÷Á¢ ±¸¼ºµÇ°í ÀÎÁõ¼­¿¡ NUL·Î Á¾·áµÇÁö ¾ÊÀº ASN1_STRING ±¸Á¶°¡ Æ÷ÇÔµÈ °æ¿ì). X509_get1_email(), X509_REQ_get1_email() ¹× X509_get1_ocsp() ÇÔ¼ö¿¡¼­µµ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ¾ÇÀÇÀûÀÎ ÇàÀ§ÀÚ°¡ ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ASN1_STRINGÀ» Á÷Á¢ ±¸¼ºÇÑ ´ÙÀ½ ¿µÇâÀ» ¹Þ´Â OpenSSL ±â´É Áß Çϳª¸¦ ÅëÇØ Ã³¸®Çϵµ·Ï Çϸé ÀÌ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·Î ÀÎÇØ Ãæµ¹ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù(¼­ºñ½º °ÅºÎ °ø°Ý À¯¹ß).
¶ÇÇÑ °³ÀÎ ¸Þ¸ð¸® ÄÜÅÙÃ÷(¿¹: °³ÀÎ Å° ¶Ç´Â ¹Î°¨ÇÑ ÀÏ¹Ý ÅؽºÆ®)°¡ °ø°³µÉ ¼ö ÀÖ½À´Ï´Ù. OpenSSL 1.0.2za¿¡¼­ ¼öÁ¤µÇ¾ú½À´Ï´Ù(1.0.2-1.0.2y¿¡ ¿µÇâÀ» ¹ÞÀ½). (CVE-2021-3712)
* Âü°í »çÀÌÆ®:
https://github.com/openssl/openssl/commit/ccb0a11145ee72b042d10593a64eaf9e8a55ec12
https://www.openssl.org/news/secadv/20210824.txt

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
1.0.2za ÀÌÀüÀÇ OpenSSL 1.0.2x
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.2za ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2021-3712 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)