Ãë¾àÁ¡ID |
22982 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ OpenSSL ¹öÀüÀº 1.0.2za ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼ 1.0.2za ±Ç°í¿¡ ¾ð±ÞµÈ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- ASN.1 ¹®ÀÚ¿Àº ¹®ÀÚ¿ µ¥ÀÌÅ͸¦ º¸À¯ÇÏ´Â ¹öÆÛ¿Í ¹öÆÛ ±æÀ̸¦ º¸À¯ÇÏ´Â Çʵ带 Æ÷ÇÔÇÏ´Â ASN1_STRING ±¸Á¶·Î OpenSSL ³»¿¡¼ ³»ºÎÀûÀ¸·Î Ç¥ÇöµË´Ï´Ù. ÀÌ°ÍÀº NUL(0) ¹ÙÀÌÆ®·Î ³¡³ª´Â ¹®ÀÚ¿ µ¥ÀÌÅÍ¿¡ ´ëÇÑ ¹öÆÛ·Î ´Ù½Ã ³ªÅ¸³ª´Â ÀÏ¹Ý C ¹®ÀÚ¿°ú ´ëÁ¶µË´Ï´Ù. ¾ö°ÝÇÑ ¿ä±¸ »çÇ×Àº ¾Æ´ÏÁö¸¸ OpenSSLÀÇ ÀÚü d2i ÇÔ¼ö(¹× ±âŸ À¯»çÇÑ ±¸¹® ºÐ¼® ±â´É)¸¦ »ç¿ëÇÏ¿© ±¸¹® ºÐ¼®µÇ´Â ASN.1 ¹®ÀÚ¿°ú ASN1_STRING_set() ÇÔ¼ö·Î °ªÀÌ ¼³Á¤µÈ ¹®ÀÚ¿Àº Ãß°¡·Î NUL¿¡¼ ¹ÙÀÌÆ® ¹è¿À» Á¾·áÇÕ´Ï´Ù. ASN1_STRING ±¸Á¶. ±×·¯³ª ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ASN1_STRING ¹è¿¿¡¼ µ¥ÀÌÅÍ ¹× ±æÀÌ Çʵ带 Á÷Á¢ ¼³Á¤ÇÏ¿© ¹ÙÀÌÆ® ¹è¿À» NUL Á¾·áÇÏÁö ¾Ê´Â À¯È¿ÇÑ ASN1_STRING ±¸Á¶¸¦ Á÷Á¢ ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ASN1_STRING_set0() ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© ¹ß»ýÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ASN.1 µ¥ÀÌÅ͸¦ ÀμâÇÏ´Â ¼ö¸¹Àº OpenSSL ÇÔ¼ö´Â ASN1_STRING ¹ÙÀÌÆ® ¹è¿ÀÌ NUL Á¾·áµÉ °ÍÀ̶ó°í °¡Á¤ÇÏ´Â °ÍÀ¸·Î ³ªÅ¸³µ½À´Ï´Ù. ºñ·Ï ÀÌ°ÍÀÌ Á÷Á¢ ±¸¼ºµÈ ¹®ÀÚ¿¿¡ ´ëÇØ º¸ÀåµÇÁö´Â ¾ÊÁö¸¸. ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ÀμâÇÒ ASN.1 ±¸Á¶¸¦ ¿äûÇÏ°í ÇØ´ç ASN.1 ±¸Á¶°¡ µ¥ÀÌÅÍ Çʵ带 Á¾·áÇÏ´Â NUL ¾øÀÌ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ÀÇÇØ Á÷Á¢ ±¸¼ºµÈ ASN1_STRINGÀ» Æ÷ÇÔÇÏ´Â °æ¿ì Àб⠹öÆÛ ¿À¹ö·±ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÎÁõ¼ÀÇ À̸§ Á¦¾à ó¸® Áß¿¡µµ µ¿ÀÏÇÑ ÀÏÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù(¿¹: ÀÎÁõ¼°¡ OpenSSL ±¸¹® ºÐ¼® ±â´ÉÀ» ÅëÇØ ·ÎµåÇÏ´Â ´ë½Å ¾ÖÇø®ÄÉÀ̼ǿ¡ ÀÇÇØ Á÷Á¢ ±¸¼ºµÇ°í ÀÎÁõ¼¿¡ NUL·Î Á¾·áµÇÁö ¾ÊÀº ASN1_STRING ±¸Á¶°¡ Æ÷ÇÔµÈ °æ¿ì). X509_get1_email(), X509_REQ_get1_email() ¹× X509_get1_ocsp() ÇÔ¼ö¿¡¼µµ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ¾ÇÀÇÀûÀÎ ÇàÀ§ÀÚ°¡ ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ ASN1_STRINGÀ» Á÷Á¢ ±¸¼ºÇÑ ´ÙÀ½ ¿µÇâÀ» ¹Þ´Â OpenSSL ±â´É Áß Çϳª¸¦ ÅëÇØ Ã³¸®Çϵµ·Ï Çϸé ÀÌ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·Î ÀÎÇØ Ãæµ¹ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù(¼ºñ½º °ÅºÎ °ø°Ý À¯¹ß). ¶ÇÇÑ °³ÀÎ ¸Þ¸ð¸® ÄÜÅÙÃ÷(¿¹: °³ÀÎ Å° ¶Ç´Â ¹Î°¨ÇÑ ÀÏ¹Ý ÅؽºÆ®)°¡ °ø°³µÉ ¼ö ÀÖ½À´Ï´Ù. OpenSSL 1.0.2za¿¡¼ ¼öÁ¤µÇ¾ú½À´Ï´Ù(1.0.2-1.0.2y¿¡ ¿µÇâÀ» ¹ÞÀ½). (CVE-2021-3712) * Âü°í »çÀÌÆ®: https://github.com/openssl/openssl/commit/ccb0a11145ee72b042d10593a64eaf9e8a55ec12 https://www.openssl.org/news/secadv/20210824.txt
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: 1.0.2za ÀÌÀüÀÇ OpenSSL 1.0.2x Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
OpenSSL À¥ »çÀÌÆ®ÀÎ http://www.openssl.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â OpenSSLÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.2za ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2021-3712 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|