CVE-2015-0760, CVE-2015-0761, CVE-2015-0762
CVE-2015-0763, CVE-2015-0764
[º¸¾È´º½º ¹®°¡¿ë] ÇöÁö ½Ã°¢À¸·Î 6¿ù 4ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 4ÀÏ¿¡¼ 5ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÔ´Ï´Ù.
1. CVE-2015-0760
½Ã½ºÄÚÀÇ ASA ¼ÒÇÁÆ®¿þ¾î 8.2.2.13 ÀÌÀü ¹öÀü Áß¿¡¼ 7.x, 8.0.x, 8.1.x, 8.2.x¿¡ IKEv1À» ±¸ÇöÇÒ ¶§ ³ªÅ¸³ª´Â ¹ö±×·Î ¿ø°Ý¿¡¼ ÀÎÁõÀ» ¹ÞÀº »ç¿ëÀÚ°¡ XAUTH¶ó´Â ÀÎÁõ ½Ã½ºÅÛÀ» IKEv1 ÆÐŶÀ» ÅëÇØ ¿ìȸÇÒ ¼ö ÀÖµµ·Ï ÇØÁÝ´Ï´Ù. ¹ö±× ID CSCus47259¿Í µ¿ÀÏÇÕ´Ï´Ù.
2. CVE-2015-0761
½Ã½ºÄÚÀÇ AnyConnect Secure Mobility Client 4.0(2052) ÀÌÀü ¸®´ª½º ¹öÀü Áß 3.1(8009)°ú 4.x¿¡ ÇØ´çÇÏ´Â °ÍÀ¸·Î, ƯÁ¤µÇÁö ¾ÊÀº ³»ºÎ ÇÔ¼ö¸¦ Á¦´ë·Î ±¸ÇöÇÏÁö ¾Ê¾Æ ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ ·çÆ® ±ÇÇÑÀ» °®°Ô ÇØÁÖ´Â ¹ö±×ÀÔ´Ï´Ù. ¹ö±× ID CSCus86790°ú µ¿ÀÏÇÕ´Ï´Ù.
3. CVE-2015-0762
½Ã½ºÄÚÀÇ Unified MeetingPlace 8.6(1.2)¿Í 8.6(1.9)¿¡ ÀÖ´Â °ü¸® ÀÎÅÍÆäÀ̽º¿¡¼ ¹ß°ßµÈ XSS Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» Á¶ÀÛµÈ URL °ªÀ» ÅëÇØ ÁÖÀÔÇÒ ¼ö ÀÖµµ·Ï ÇØÁÝ´Ï´Ù. ¹ö±× ID CSCuu51400°ú µ¿ÀÏÇÕ´Ï´Ù.
4. CVE-2015-0763
½Ã½ºÄÚÀÇ Unified MeetingPlace 8.6(1.2)¿¡ ÀÖ´Â ¹ö±×·Î ¼¼¼Ç ID¸¦ Á¦´ë·Î È®ÀÎÇÏÁö ¾Ê¾Æ ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ ¼¼¼Ç Á¤º¸¿¡ Á¢±ÙÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. ¹ö±× ID´Â CSCuu60338°ú °°½À´Ï´Ù.
5. CVE-2015-0764
½Ã½ºÄÚÀÇ Unified MeetingPlace 8.6(1.9)¿¡ ÀÖ´Â ¹ö±×·Î ¿ø°ÝÀÇ »ç¿ëÀÚ°¡ ÀÓÀÇÀÇ ÆÄÀÏÀ» Á¶ÀÛµÈ ¸®¼Ò½º ¿äûÀ» ÅëÇØ ÀоîµéÀÏ ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù. ¹ö±× ID´Â CSCus95603°ú °°½À´Ï´Ù.
Copyrighted 2015. UBM-Tech. 117153:0515BC
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>