0. ç°¡åãªSLOTHæ»æã®ã¾ã¨ã æåã«ç°¡åãªã¾ã¨ããæ¸ãã¦ããã¾ããé·æã«ãªããããªã®ã§ãèªãã®ã大å¤ãªæ¹ã¯ããã ãè¦ã¦ããã¦ãã ããã MD5ããã·ã¥ã¯æ¢ã«å®å
¨ã§ã¯ãªãã証ææ¸ã®ç½²åæ¹å¼ã§ã®å©ç¨ã¯åæ¢ããã¦ããããå¾æ¹äºæã®ãããã³ãã·ã§ã¤ã¯ãã¼ã¿ã®ç½²åæ¹å¼ã«RSA-MD5ãä»ã§ãå©ç¨ã§ããTLSå®è£
ãå¹¾ã¤ãåå¨ãã¦ãã(Firefox NSS, Javaç)ã å
é±ãINRIAã°ã«ã¼ãããããã·ã¥è¡çªãå©ç¨ãã¦å®éã«TLSãç ´ãæ»æ(SLOTH)ãå
¬éãããããããåããããã¤ãã®å®è£
ã§RSA-MD5ãå®å
¨ã«å©ç¨ä¸è½ã«ããä¿®æ£ãè¡ããã(CVE-2015-7575)ã SLOTHã§ã¯ãSHA1ãTLSãIKEãSSHã«å¯¾ããæ»æã«ã¤ãã¦ãè©ä¾¡ãè¡ããå¹¾ã¤ãã¯å
¨ãç¾å®çã«ä¸å¯è½ãªã¬ãã«ã§ã¯ãªããã¨ã示ããããMD5ã¨SHA-1ã§TLSãã³ãã·ã§ã¤ã¯ã®å®å
¨æ§ãæ
ä¿ãã¦ããTLS1.0/
{{#tags}}- {{label}}
{{/tags}}