CVE-2015-0536, CVE-2015-0537
[º¸¾È´º½º ÁÖ¼ÒÇü] ÇöÁö ½Ã°¢À¸·Î 8¿ù 20ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 20ÀÏ¿¡¼ 21ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÔ´Ï´Ù.
1. CVE-2015-0533
EMC RSA BSAFE MES 4.0.x, 4.0.8, 4.1.x, 4.1.3 ÀÌÀü ¹öÀü ¹× RSA BSAFE SSL-C 2.8.9 ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ ServerKeyExchange ¸Þ½ÃÁö¸¦ ÅëÇØ ECDHE-to-ECDH °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
2. CVE-2015-0534
EMC RSA BSAFE MES 4.0.x, 4.0.8, 4.1.x, 4.1.3 ÀÌÀü ¹öÀü ¹× RSA BSAFE Crypto-J 6.2 ÀÌÀü ¹öÀü, RSA BSAFE SSL-J 6.2 ÀÌÀü ¹öÀü, RSA BSAFE SSL-C 2.8.9 ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ Áõ¸í¼ÀÇ »çÀεÇÁö ¾ÊÀº ºÎºÐ¿¡ ÀÖ´Â Á¶ÀÛµÈ µ¥ÀÌÅ͸¦ ÅëÇØ Áö¹® µîÀ» ÅëÇÑ º¸¾È ¸ÞÄ¿´ÏÁòÀ» ¸ðµÎ ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
3. CVE-2015-0535
EMC RSA BSAFE MES 4.0.x, 4.0.8, 4.1.x, 4.1.3 ÀÌÀü ¹öÀü ¹× RSA BSAFE SSL-C 2.8.9 ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ FREAK°ú ¿¬°üµÈ Á¶ÀÛµÈ TLS Æ®·¡ÇÈÀ» ÅëÇØ EXPORT_RSA ciphers¿¡ cipher-downgrade ´Ù¿î·Îµå °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
4. CVE-2015-0536
EMC RSA BSAFE MES 4.0.x, 4.0.8, 4.1.x, 4.1.3 ÀÌÀü ¹öÀü ¹× RSA BSAFE SSL-C 2.8.9 ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ ClientKeyExchange ¸Þ½ÃÁö¸¦ ÅëÇØ ¼ºñ½º °ÅºÎ¸¦ ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
5. CVE-2015-0537
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x, 4.0.8, 4.1.x, 4.1.3 ÀÌÀü ¹öÀü, RSA BSAFE Crypto-C Micro Edition (Crypto-C ME) 4.0.4, 4.1 ÀÌÀü ¹öÀü, RSA BSAFE SSL-C 2.8.9 ¹öÀü¿¡¼ ¹ß°ßµÈ Á¤ºÎ ¾ð´õÇ÷οì Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ Á¶ÀÛµÈ base64 µ¥ÀÌÅ͸¦ ÅëÇØ ¼ºñ½º °ÅºÎ¸¦ ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. Copyrighted 2015. UBM-Tech. 117153:0515BC
[±¹Á¦ºÎ ÁÖ¼ÒÇü ±âÀÚ(sochu@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>