èæ± ã§ããCCS Injectionèå¼±æ§(CVE-2014-0224)çºè¦ã®çµç·¯ã«ã¤ãã¦ç´¹ä»ãã¾ãã ãã°ã®ç°¡åãªè§£èª¬ OpenSSLããã³ãã·ã§ã¼ã¯ä¸ã«ä¸é©åãªç¶æ ã§ChangeCipherSpecãåçãã¦ãã¾ãã®ãä»åã®ãã°ã§ãã ãã®ãã°ã¯OpenSSLã®æåã®ãªãªã¼ã¹ããåå¨ãã¦ãã¾ããã é常ã®ãã³ãã·ã§ã¼ã¯ã§ã¯ãå³ã®å³ã®ãããªé åºã§ã¡ãã»ã¼ã¸ã交æãã¾ã(RFC5246 The Transport Layer Security (TLS) Protocol Version 1.2 §7.3ããä½æ)ã ChangeCipherSpecã¯å¿ ããã®ä½ç½®ã§è¡ããã¨ã«ãªã£ã¦ãã¾ããOpenSSLãChangeCipherSpecããã®ã¿ã¤ãã³ã°ã§éä¿¡ãã¾ãããåä¿¡ã¯ä»ã®ã¿ã¤ãã³ã°ã§ãè¡ãããã«ãªã£ã¦ãã¾ããããããæªç¨ãããã¨ã§ãæ»æè ãéä¿¡ã解èªã»æ¹ããå¯è½ã§ãã çºè¦ã®å°é£ã
{{#tags}}- {{label}}
{{/tags}}