[º¸¾È´º½º ¹Î¼¼¾Æ] OpenSSLÀº ÇöÁö½Ã°£ 3¿ù 1ÀÏÀÚ·Î SSLv2 ÇÁ·ÎÅäÄÝ(Protocol)¿¡ ´ëÇÑ ±ä±Þ ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
SSL Ãë¾àÁ¡À» ÀÌ¿ëÇÑ ½ÅÁ¾ °ø°Ý ¹æ½ÄÀÎ DROWN(Decrypting RSA with Obsolete and Weakened eNcryption), CacheBleed¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ® µîÀ¸·Î, SSLv2 ÇÁ·ÎÅäÄÝ ºñÈ°¼ºÈ ±âº» ¼³Á¤ ¹× SSLv2 EXPORT ¾ÏÈ£È Á¦°Å µîÀÇ ³»¿ëÀÌ Æ÷ÇԵŠÀÖ´Ù.
ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â OpenSSL 1.0.1, 1.0.2 »ç¿ëÀÚ´Â °¢°¢ 1.0.1s, 1.0.2g·Î ¾÷µ¥ÀÌÆ®ÇÏ¸é µÈ´Ù.
¡ãÃë¾àÁ¡ ³»¿ë ¹× ±Ç°í »çÇ×
ÀÌ¿Í °ü·Ã º¸´Ù ÀÚ¼¼ÇÑ ¹®ÀÇ»çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø ¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
https://www.openssl.org/news/secadv/20160301.txt
[¿ë¾î ¼³¸í]
CacheBleed: ÀÎÅÚ ÇÁ·Î¼¼¼ÀÇ Cache-bank Ãæµ¹·Î ÀÎÇÑ Á¤º¸ ³ëÃâÀ» ÀÌ¿ëÇÑ ºÎä³Î °ø°Ý
DFB(Double-Free Bug): Èü ¿À¹öÇ÷ο쿡 ±â¹ÝÀ» µÐ °ø°ÝÀ¸·Î, ¿øÇÏ´Â À§Ä¡ÀÇ ¸Þ¸ð¸®¸¦ »ç¿ëÇϱâ À§ÇÑ ¹æ¹ý
³Î Æ÷ÀÎÅÍ ¿ªÂüÁ¶(Null Pointer Dereference): ³Î Æ÷ÀÎÅÍ¿¡ ÀÓÀÇÀÇ °ªÀ» ´ëÀÔÇÏ¿© ¹ß»ýÇÏ´Â ¿¡·¯
Èü Ä¿·´¼Ç(Heap Corruption): µ¿Àû ÇÒ´çÇÑ Å©±âº¸´Ù ´õ Å« ¿µ¿ª¿¡ Á¢±ÙÇÔÀ¸·Î½á ¹ß»ýÇÏ´Â ¿¡·¯
ºÎä³Î °ø°Ý(Side Channel Attack): ¾Ë°í¸®ÁòÀÇ ¾àÁ¡À» ã°Å³ª ¹«Â÷º° °ø°ÝÀ» ÇÏ´Â ´ë½Å ¾Ïȣü°èÀÇ ¹°¸®ÀûÀÎ ±¸Çö°úÁ¤ÀÇ Á¤º¸¸¦ ±â¹ÝÀ¸·Î ÇÏ´Â °ø°Ý¹æ¹ý
ºÐÇÒ Á¤º¹ ¾Ë°í¸®Áò(Divide-and-conquer): ±×´ë·Î ÇØ°áÇÒ ¼ö ¾ø´Â ¹®Á¦¸¦ ÀÛÀº ¹®Á¦·Î ºÐÇÒÇÏ¿© ¹®Á¦¸¦ ÇØ°áÇÏ´Â ¹æ¹ý
Bleichenbacher °ø°Ý: RSA ¾ÏÈ£È ¸Þ½ÃÁö ³»¿ëÀ» Á¡Â÷ÀûÀ¸·Î ³ëÃâÇϱâ À§ÇÑ °ø°Ý
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>