OpenSSL 1.1.1j, WolfSSL 4.7.0 ๋ฐ LibreSSL 3.2.4 ์—…๋ฐ์ดํŠธ

OpenSSL ์•”ํ˜ธํ™” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ 1.1.1j์˜ ์œ ์ง€ ๊ด€๋ฆฌ ๋ฆด๋ฆฌ์Šค๊ฐ€ ์ถœ์‹œ๋˜์–ด ๋‘ ๊ฐ€์ง€ ์ทจ์•ฝ์ ์ด ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • CVE-2021-23841์€ X509_issuer_and_serial_hash() ํ•จ์ˆ˜์˜ NULL ํฌ์ธํ„ฐ ์—ญ์ฐธ์กฐ๋กœ, ๋ฐœ๊ธ‰์ž ํ•„๋“œ์— ์ž˜๋ชป๋œ ๊ฐ’์ด ์žˆ๋Š” X509 ์ธ์ฆ์„œ๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ์ด ํ•จ์ˆ˜๋ฅผ ํ˜ธ์ถœํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์ถฉ๋Œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • CVE-2021-23840์€ EVP_CipherUpdate, EVP_EncryptUpdate ๋ฐ EVP_DecryptUpdate ํ•จ์ˆ˜์˜ ์ •์ˆ˜ ์˜ค๋ฒ„ํ”Œ๋กœ๋กœ, ๊ฐ’ 1์„ ๋ฐ˜ํ™˜ํ•˜์—ฌ ์„ฑ๊ณต์ ์ธ ์ž‘์—…์„ ๋‚˜ํƒ€๋‚ด๊ณ  ํฌ๊ธฐ๋ฅผ ์Œ์ˆ˜ ๊ฐ’์œผ๋กœ ์„ค์ •ํ•˜์—ฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์ถฉ๋Œํ•˜๊ฑฐ๋‚˜ ์ค‘๋‹จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ •์ƒ์ ์ธ ํ–‰๋™.
  • CVE-2021-23839๋Š” SSLv2 ํ”„๋กœํ† ์ฝœ ์‚ฌ์šฉ์„ ์œ„ํ•œ ๋กค๋ฐฑ ๋ณดํ˜ธ ๊ตฌํ˜„์˜ ๊ฒฐํ•จ์ž…๋‹ˆ๋‹ค. ์ด์ „ ๋ธŒ๋žœ์น˜ 1.0.2์—์„œ๋งŒ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

LibreSSL 3.2.4 ํŒจํ‚ค์ง€์˜ ๋ฆด๋ฆฌ์Šค๋„ ๋ฐœํ‘œ๋˜์—ˆ์œผ๋ฉฐ, OpenBSD ํ”„๋กœ์ ํŠธ๋Š” ๋” ๋†’์€ ์ˆ˜์ค€์˜ ๋ณด์•ˆ ์ œ๊ณต์„ ๋ชฉํ‘œ๋กœ ํ•˜๋Š” OpenSSL ํฌํฌ๋ฅผ ๊ฐœ๋ฐœํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๋ฆด๋ฆฌ์Šค๋Š” ์ด์ „ ์ฝ”๋“œ์˜ ๋ฒ„๊ทธ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ๋ฐ”์ธ๋”ฉ์ด ์žˆ๋Š” ์ผ๋ถ€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ์ค‘๋‹จ์œผ๋กœ ์ธํ•ด LibreSSL 3.1.x์—์„œ ์‚ฌ์šฉ๋œ ์ด์ „ ์ธ์ฆ์„œ ํ™•์ธ ์ฝ”๋“œ๋กœ ๋˜๋Œ๋ฆฐ ๊ฒƒ์œผ๋กœ ์ฃผ๋ชฉํ•  ๋งŒํ•ฉ๋‹ˆ๋‹ค. ํ˜์‹  ์ค‘์—์„œ TLSv1.3์— ๋‚ด๋ณด๋‚ด๊ธฐ ๋ฐ ์ž๋™ ์ฒด์ธ ๊ตฌ์„ฑ ์š”์†Œ ๊ตฌํ˜„์„ ์ถ”๊ฐ€ํ•œ ๊ฒƒ์ด ๋ˆˆ์— ๋•๋‹ˆ๋‹ค.

๋˜ํ•œ ์‚ฌ๋ฌผ ์ธํ„ฐ๋„ท ์žฅ์น˜, ์Šค๋งˆํŠธ ํ™ˆ ์‹œ์Šคํ…œ, ์ž๋™์ฐจ ์ •๋ณด ์‹œ์Šคํ…œ, ๋ผ์šฐํ„ฐ ๋ฐ ํœด๋Œ€ํฐ๊ณผ ๊ฐ™์ด ํ”„๋กœ์„ธ์„œ ๋ฐ ๋ฉ”๋ชจ๋ฆฌ ๋ฆฌ์†Œ์Šค๊ฐ€ ์ œํ•œ์ ์ธ ์ž„๋ฒ ๋””๋“œ ์žฅ์น˜์— ์‚ฌ์šฉํ•˜๋„๋ก ์ตœ์ ํ™”๋œ ์†Œํ˜• ์•”ํ˜ธํ™” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์ธ WolfSSL 4.7.0์ด ์ƒˆ๋กœ ์ถœ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. . ์ฝ”๋“œ๋Š” C ์–ธ์–ด๋กœ ์ž‘์„ฑ๋˜์—ˆ์œผ๋ฉฐ GPLv2 ๋ผ์ด์„ผ์Šค์— ๋”ฐ๋ผ ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค.

์ƒˆ ๋ฒ„์ „์—๋Š” RFC 5705(TLS์šฉ ํ‚ค ์ž๋ฃŒ ๋‚ด๋ณด๋‚ด๊ธฐ) ๋ฐ S/MIME(๋ณด์•ˆ/๋‹ค์šฉ๋„ ์ธํ„ฐ๋„ท ๋ฉ”์ผ ํ™•์žฅ)์— ๋Œ€ํ•œ ์ง€์›์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์žฌํ˜„ ๊ฐ€๋Šฅํ•œ ๋นŒ๋“œ๋ฅผ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•ด "--enable-reproducible-build" ํ”Œ๋ž˜๊ทธ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. OpenSSL๊ณผ์˜ ํ˜ธํ™˜์„ฑ์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•ด SSL_get_verify_mode API, X509_VERIFY_PARAM API ๋ฐ X509_STORE_CTX๊ฐ€ ๋ ˆ์ด์–ด์— ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋งคํฌ๋กœ WOLFSSL_PSK_IDENTITY_ALERT๋ฅผ ๊ตฌํ˜„ํ–ˆ์Šต๋‹ˆ๋‹ค. TLS 12 ์„ธ์…˜ ํ‹ฐ์ผ“์„ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ  TLS 1.2์šฉ์œผ๋กœ ์œ ์ง€ํ•˜๋Š” ์ƒˆ๋กœ์šด ๊ธฐ๋Šฅ _CTX_NoTicketTLSv1.3๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€