CVE-2015-0531, CVE-2015-0538, CVE-2015-0701
CVE-2015-0715, CVE-2015-0716
[º¸¾È´º½º ¹®°¡¿ë] ÇöÁö ½Ã°¢À¸·Î 5¿ù 6ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 6ÀÏ¿¡¼ 7ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÔ´Ï´Ù.
1. CVE-2015-0531
EMCÀÇ SourceOne Email Management 7.2 ÀÌÀü ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î ·Î±×ÀÎ ½ÃµµÀÇ ¹Ýº¹ ¿À·ù¿¡ ´ëÇÑ ¹æ¾î±âÀç°¡ ¾ø½À´Ï´Ù. Áï, ºê·çÆ®Æ÷½º °ø°ÝÀÌ °¡´ÉÇÏ´Ù´Â °ÍÀÌÁÒ.
2. CVE-2015-0538
EMC AutoStart 5.4.x¿Í 5.5.x ¹öÀü¿¡ ÀÖ´Â ftagent.exe¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ÇØÄ¿°¡ ÀÓÀÇÀÇ ¸í·ÉÀ» Á¶ÀÛµÈ ÆÐŶÀ» ÅëÇØ ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁÝ´Ï´Ù.
3. CVE-2015-0701
½Ã½ºÄÚÀÇ UCS Central Software 1.2 ÀÌÇÏ ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ »ç¿ëÀÚ°¡ Á¶ÀÛµÈ HTTP ¿äûÀ» ÅëÇØ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. Bug ID CSCut46961°ú µ¿ÀÏÇÕ´Ï´Ù.
4. CVE-2015-0715
½Ã½ºÄÚÀÇ Unified Communications Manager 11.0(0.98000.225)¿¡ ÀÖ´Â °ü¸®ÀÚ À¥ ÀÎÅÍÆäÀ̽º¿¡¼ ¹ß°ßµÈ SQL ÀÎÁ§¼Ç Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ·Î±×ÀÎÇÑ »ç¿ëÀÚ°¡ ÀÓÀÇÀÇ SQL ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. Bug ID CSCut33447°ú CSCut33608°ú µ¿ÀÏÇÕ´Ï´Ù.
5. CVE-2015-0716
½Ã½ºÄÚÀÇ Unity Connection 11.0(0.98000.225)°ú 11.0(0.98000.332)ÀÇ CUCReports ÆäÀÌÁö¿¡¼ ¹ß°ßµÈ CSRF Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ »ç¿ëÀÚ°¡ ÀÓÀÇÀÇ »ç¿ëÀÚ ±ÇÇÑÀ» ÇÏÀÌÀçÅ· Çϵµ·Ï ÇØÁÝ´Ï´Ù. Bug ID CSCut33659¿Í µ¿ÀÏÇÕ´Ï´Ù.
@DARKReading
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>