ãµã¼ãã¹çµäºã®ãç¥ãã NAVERã¾ã¨ãã¯2020å¹´9æ30æ¥ããã¡ã¾ãã¦ãµã¼ãã¹çµäºãããã¾ããã ç´11å¹´éãNAVERã¾ã¨ãããå©ç¨ã»ãæ顧ããã ãèª ã«ãããã¨ããããã¾ããã
ãµã¼ãã¹çµäºã®ãç¥ãã NAVERã¾ã¨ãã¯2020å¹´9æ30æ¥ããã¡ã¾ãã¦ãµã¼ãã¹çµäºãããã¾ããã ç´11å¹´éãNAVERã¾ã¨ãããå©ç¨ã»ãæ顧ããã ãèª ã«ãããã¨ããããã¾ããã
2014å¹´04æ07æ¥ã OpenSSL æ å ±æ¼ããã許ãã¦ãã¾ãèå¼±æ§(CVE-2014-0160) ï½Heartbleed åé¡ï½ ã«ã¤ãã¦å ±åããã¾ããã ã¤ã³ã·ãã³ãæ å ±æ´»ç¨ãã¬ã¼ã ã¯ã¼ã¯æ¤è¨ WGã§ã¯ãã¤ã³ã·ãã³ã対å¿æè¡èª¿æ» WGãæ¥æ¬ã·ã¼ãµã¼ãåè°ä¼ã«å çãã¦ãããã¼ã ã«ååãå¾ã¦ãã¤ã³ã·ãã³ãçºçãäºåã«äºé²ããæªç½®ã¨ãã¦ããOpenSSL æ å ±æ¼ããã許ãã¦ãã¾ãèå¼±æ§ ï½ Heartbleed åé¡ï½ãã«é¢ããå ¬éæ å ±ã調æ»ããæ¬ã¬ãã¼ãã«ã¾ã¨ãã¾ããã ã»OpenSSL æ å ±æ¼ããã許ãã¦ãã¾ãèå¼±æ§ ï½ Heartbleed åé¡ï½ ã¨ã¯ ã»å¯¾ç ã»ãã³ãæ å ± ã»è¦³æ¸¬æ¥è¨ ã»æ´æ°å±¥æ´ OpenSSL æ å ±æ¼ããã許ãã¦ãã¾ãèå¼±æ§ ï½ Heartbleed åé¡ï½ ã¯ã OpenSSL ã® TLS/DTLS ç¨ Heartbeat æ¡å¼µã®å®è£ ã«èµ·å ããæ å ±æ¼ããã許
HeartBleed(CVE-2014-0160)é¢ä¿ã®ãªã³ã¯éãèªåã®ã¡ã¢ç¨ãªã®ã§ä¸æ£ç¢ºã§ãã HeartBleedã®å½±é¿å¯¾è±¡ã¨ãªãOpenSSLãã¼ã¸ã§ã³ 以ä¸ã®ãã¼ã¸ã§ã³ãå½±é¿ãåãã¾ããä½ããã·ã¹ãã ã«ãã£ã¦ã¯åå ã¨ãªã£ã¦ããheartbeatæ©è½ãç¡å¹åããã¦ããå ´åãããããããã¼ã¸ã§ã³ãä¸è´ããã ãã§å½è©²èå¼±æ§ã®å½±é¿ãåãããã¯ç¢ºå®ãã¾ããã (1) OpenSSL 1.0.1ç³» ãã¼ã¸ã§ã³å ãªãªã¼ã¹ææ CVE-2014-0160 OpenSSL 1.0.1 2012/03/14 èå¼±æ§ãã OpenSSL 1.0.1a 2012/04/19 èå¼±æ§ãã OpenSSL 1.0.1b 2012/04/26 èå¼±æ§ãã OpenSSL 1.0.1c 2012/05/10 èå¼±æ§ãã OpenSSL 1.0.1d 2013/02/05 èå¼±æ§ãã OpenSSL 1.0.1e
JVNãJPCERT/CCã®è¨äºããã¾ãã«ãããã£ã¨æ¸ããã¦ãã¦ãå ·ä½çãªãªã¹ã¯ãæ³åãã¥ããã¨æãã®ã§èª¬æãã¾ãã ä»åç£æ¥ (ä»ãã¥ã¼ã¹è¦ã¦æ¥ãããä¸è¡ã§æãã¦æ¬²ããã¨ãã人åãã®ã¾ã¨ã) ã¤ã³ã¿ã¼ãããä¸ã®ãæå·åãã«ä½¿ããã¦ããOpenSSLã¨ããã½ããã¦ã§ã¢ã2å¹´éå£ãã¦ãã¾ããã ãã®ã½ããã¦ã§ã¢ã¯ä¾¿å©ãªã®ã§ãFacebookã ã¨ãYouTubeã ã¨ãããã¡ãã¡ã®ã¦ã§ããµã¤ãã§ä½¿ã£ã¦ãã¾ããã ä»ã®äººã®å ¥åããIDã¨ããã¹ã¯ã¼ãã¨ãã¯ã¬ã«çªå·ã¨ãããæªã人ãè¦ããã¨ãã§ãã¦ãã¾ãã¾ãã(å®éã«æ¼ãã¦ãä¾) ä»ã«ãè²ã æ¼ãã¦ã¾ãããã¨ããããã¨ã³ã¸ãã¢ä»¥å¤ã®äººãè¦ãã¦ããã¹ãã¯ããã¾ã§ã§OKã§ããããå°ãåãããããæ å ±ã以ä¸ã«ããã¾ãã OpenSSL ã®èå¼±æ§ã«å¯¾ãããã¦ã§ããµã¤ãå©ç¨è ï¼ä¸è¬ã¦ã¼ã¶ï¼ã®å¯¾å¿ã«ã¤ã㦠ã¾ã ç´ã£ã¦ããªãã¦ã§ããµã¤ããããã°ãå ã å£ãã¦ããªãã¦ã§ã
å¿ è¦ãªæ å ±ã¯ http://heartbleed.com/ ã«ã¾ã¨ã¾ã£ã¦ããã®ã§ãããè±èªã ãé·ããã£ã¦äººã®ããã«æçã«ã¾ã¨ãã¦ããã¾ãã ã©ãããã°ããã®ã OpenSSL 1.0.1ã1.0.1fã使ã£ã¦ããªããã°ã»ã¼ã ãã¦ã¯ã¾ãå ´åã«ã¯ãä¸å»ãæ©ããã¼ã¸ã§ã³ã¢ãããã¦ããµã¼ããã¨åèµ·å(ãããã²ã¨ã¯ãµã¼ãã¹åä½ã§ãOKããã ãreloadã§ã¯ã ããªãã¨ã) SSL証ææ¸ã§ãµã¼ããå ¬éãã¦ãããªããç§å¯éµããä½ãç´ãã¦è¨¼ææ¸ãåçºè¡ããéå»ã®è¨¼ææ¸ã失å¹ããã(æ«å°¾ã«é¢é£ãªã³ã¯ãã)ã ãµã¼ããå ¬éãã¦ããªãå ´åããå¤é¨ã¸ã®SSLéä¿¡ãããã°å½±é¿ãåããã®ã§ã詳ããç²¾æ»ããã PFS(perfect forward secrecy)ãå©ç¨ãã¦ããªãå ´åãéå»ã®éä¿¡å 容ã復å·ãããå¯è½æ§ãããããã詳ããç²¾æ»ããã æ¼æ´©ããæ å ±ã®å ·ä½ä¾ã¯ãOpenSSLã®èå¼±æ§ã§æ³å®ããããªã¹ã¯ã¨ãã¦
ï¼ï¼æ¥ã«éãããå µåº«çè°ä¼ã®å§å¡ä¼ã§ãèªæ°å æå±ã®äºä¸è±ä¹çè°ï¼ï¼ï¼ï¼ãç·æ§å士ã®æ§è¡çºã«ããHIVï¼ã¨ã¤ãºã¦ã¤ã«ã¹ï¼ææé²æ¢ã«åããçã®åçºæ´»åãçåè¦ããçºè¨ããã¦ãããã¨ãçãªã©ã¸ã®åæã§åãã£ãããäºä¸çè°ã¯ã社ä¼çã«èªããã¹ããããªãã¨ããã¾ãããè¡æ¿ããã¢ã®æå°ãããå¿ è¦ãããã®ãããªã©ã¨çºè¨ããã¨ãããäºä¸çè°ã¯åæã«å¯¾ããçºè¨ãããã¨ãèªããä¸ã§ããåã£ãæ§å好ï¼ãããï¼ã§æ¬æ¥ãã¤ãªã¹ã¯ã¯æ¿ç¥ã§ãã£ã¦ãã人ãã¡ã®ãã¨ãä»ã«ãéè¦èª²é¡ãããä¸ãè¡æ¿ãçå ãã¦å¯¾å¿ããå¿ è¦ã¯ãªããã¨è¿°ã¹ããçºè¨ã®æ¤åãªã©ã¯èãã¦ããªãã¨ããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}