¹ßÇ¥µÈ Ãë¾àÁ¡Àº NB_mod_exp ÇÔ¼ö¿¡¼ °ªÀ» Á¦°ö ó¸® ÇÒ ¶§ ¹ß»ýÇÏ´Â Ãë¾àÁ¡, ÀÎÁõ¼ °ËÁõ ½Ã PSS ÆĶó¹ÌÅÍ ºÎÀç·Î ÀÎÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡, X509_ATTRIBUTE ±¸Á¶Ã¼¿¡¼ ¹ß»ýÇÏ´Â OpenSSL ¸Þ¸ð¸® ´©¼ö Ãë¾àÁ¡, PSK Identify hint ó¸® Áß ¹ß»ýÇÏ´Â Race condition Ãë¾àÁ¡, ServerKyExchangeÀÇ °ªÀ» ó¸® Áß¿¡ ¹ß»ýÇÏ´Â ¼ºñ½º °ÅºÎ °ø°Ý Ãë¾àÁ¡ µîÀÌ´Ù.
ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¹öÀüÀº ´ÙÀ½°ú °°°í, ÇØ´ç ¹öÀüÀÇ »ç¿ëÀÚ´Â Á¦½ÃµÇ´Â ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇØ Ãë¾àÁ¡À» ÇØ°áÇÒ ¼ö ÀÖ´Ù.
¡âOpenSSL 1.0.2 »ç¿ëÀÚ : 1.0.2e·Î ¾÷µ¥ÀÌÆ®
¡âOpenSSL 1.0.1 »ç¿ëÀÚ : 1.0.1q·Î ¾÷µ¥ÀÌÆ®
¡âOpenSSL 1.0.0 »ç¿ëÀÚ : 1.0.0t·Î ¾÷µ¥ÀÌÆ®
¡âOpenSSL 0.9.8 »ç¿ëÀÚ : 0.9.8zh·Î ¾÷µ¥ÀÌÆ®
ÀÌ¿Í °ü·Ã º¸´Ù ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
1. https://www.openssl.org/news/secadv/20151203.txt
2. https://www.openssl.org/
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>