Adobe Flash Player, Adobe ColdFusion, Adobe Flex ÃÑ 24°³ Ãë¾àÁ¡
[º¸¾È´º½º ¹Î¼¼¾Æ] Flash Player, ColdFusion ¹× Flex¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¹ßÇ¥µÆ´Ù. À̸¦ ¹ßÇ¥ÇÑ ¾îµµºñ ÃøÀº ³·Àº ¹öÀü »ç¿ëÀÚ¿¡ ´ëÇØ ¾Ç¼ºÄÚµå °¨¿°¿¡ Ãë¾àÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÇØ°á¹æ¾È¿¡ µû¶ó ¾÷µ¥ÀÌÆ®ÇÒ °ÍÀ» ±Ç°íÇÏ°í ÀÖ´Ù.
Adobe¿¡¼ ¹ßÇ¥ÇÑ Adobe Flash PlayerÀÇ 22°³ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°´Ù.
¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡(CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, CVE-2015-3042, CVE-2015-3043)
¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â type confusion Ãë¾àÁ¡(CVE-2015-0356)
¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2015-0348)
¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â use-after-free Ãë¾àÁ¡(CVE-2015-0349, CVE-2015-0351, CVE-2015-0358, CVE-2015-3039)
¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â double-free Ãë¾àÁ¡(CVE-2015-0346, CVE-2015-0359)
¡âASLR ¿ìȸ¿¡ »ç¿ëµÇ´Â ¸Þ¸ð¸® ´©¼ö Ãë¾àÁ¡(CVE-2015-0357, CVE-2015-3040)
¡âÁ¤º¸ ´©Ãâ·Î À̾îÁú ¼ö ÀÖ´Â º¸¾È ¿ìȸ Ãë¾àÁ¡(CVE-2015-3044)
ÀÌ¿Í ÇÔ²² Adobe ColdFusionÀÇ ¡âÅ©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃ(Cross-Site Scripting(XSS)) Ãë¾àÁ¡(CVE-2015-0345)°ú Adobe FlexÀÇ ¡âÅ©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃ(Cross-Site Scripting(XSS)) Ãë¾àÁ¡(CVE-2015-1773)¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®µµ ¹ßÇ¥Çß´Ù.
¡ã¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
Adobe Flash Player »ç¿ëÀÚ Áß À©µµ¿ìÁî, ¸Æ ȯ°æÀÇ Adobe Flash Player desktop runtime »ç¿ëÀÚ´Â 17.0.0.169¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇØ Ãë¾àÁ¡À» ÇØ°áÇÒ ¼ö ÀÖ´Ù. Adobe Flash Player Download Center¿¡ ¹æ¹®ÇØ ÃֽŠ¹öÀüÀ» ¼³Ä¡Çϰųª, ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ÀÌ¿ëÇØ ¾÷±×·¹À̵åÇÏ¸é µÈ´Ù.
Adobe Flash Player Extended Support Release »ç¿ëÀÚ´Â 13.0.0.281 ¹öÀüÀ¸·Î, ¸®´ª½º ȯ°æÀÇ Adobe Flash Player »ç¿ëÀÚ´Â 11.2.202.451 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÒ ¼ö ÀÖ°í, ±¸±Û Å©·Ò ¹× À©µµ¿ì 8.x ¹öÀüÀÇ ÀÎÅÍ³Ý ÀͽºÇ÷η¯¿¡ Adobe Flash Player¸¦ ¼³Ä¡ÇÑ »ç¿ëÀÚ´Â ÀÚµ¿À¸·Î ÃֽŠ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ´Ù.
Adobe ColdFusion »ç¿ëÀÚÀÇ °æ¿ì ¾Æ·¡ÀÇ Adobe ColdFusion Help ¹®¼¸¦ ÂüÁ¶ÇØ º¸¾È¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.
¡âColdFusion 11
Adobe Flex »ç¿ëÀÚ´Â ÇØ´ç ¸µÅ©¿¡¼ index.html ÆÄÀÏÀ» ´Ù¿î·ÎµåÇØ ±âÁ¸ index.html ÆÄÀÏÀÇ Àû¿ë »çÇ×À» ¼öÁ¤ÇÑ ÈÄ web site¿¡ °á°ú¹°À» Àû¿ëÇÏ¸é µÈ´Ù.
ÀÌ¿Í °ü·ÃÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
1. htps://helpx.adobe.com/security/products/flash-player/apsb15-06.html
2. https://helpx.adobe.com/security/products/coldfusion/apsb15-07.html
3. https://helpx.adobe.com/security/products/flex/apsb15-08.html
[¿ë¾î Á¤¸®]
ColdFusion : Adobe »ç¿¡¼ ¸¸µç ¾ÖÇø®ÄÉÀ̼Ç(À¥ ¼ºñ½º) °³¹ßÀ» À§ÇÑ RAD Ç÷§Æû
Type Confusion Ãë¾àÁ¡ : °´Ã¼ÀÇ Å¸ÀÔ(type)À» È¥µ¿ÇÏ¿© ¹ß»ýÇÏ´Â ¿À·ù ¹× Ãë¾àÁ¡
Use After Free Ãë¾àÁ¡ : ¼ÒÇÁÆ®¿þ¾î ±¸Çö ½Ã µ¿Àû ȤÀº Á¤ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸®¸¦ ÇØÁ¦ÇßÀ½¿¡µµ ºÒ±¸ÇÏ°í À̸¦ °è¼Ó ÂüÁ¶(»ç¿ë)ÇÏ¿© ¹ß»ýÇÏ´Â Ãë¾àÁ¡
Double Free Ãë¾àÁ¡ : ƯÁ¤ Èü ¿µ¿ªÀ» µÎ ¹ø ÇØÁ¦½ÃÄÑ ¸Þ¸ð¸® Æ÷ÀÎÅ͸¦ Á¶ÀÛÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡
Cross-site-scripting Ãë¾àÁ¡ : °ü¸®ÀÚ°¡ ¾Æ´Ñ ÀÏ¹Ý »ç¿ëÀÚ°¡ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ »ðÀÔÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>