CVE-2015-4287, CVE-2015-4288
[º¸¾È´º½º ÁÖ¼ÒÇü] ÇöÁö ½Ã°¢À¸·Î 7¿ù 28ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 28ÀÏ¿¡¼ 29ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÔ´Ï´Ù.
1. CVE-2015-0732
WSA 9.0.0-193 ¹öÀü, ESA 8.5.6-113, 9.1.0-032, 9.1.1-000, 9.6.0-000 ¹öÀü, SMA 9.1.0-033 ¹öÀü »óÀÇ Cisco AsyncOS¿¡¼ ¹ß°ßµÈ XSS Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ ¸í½ÃµÇÁö º¤Å͸¦ ÅëÇØ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
2. CVE-2015-2974
LEMON-S PHP Gazou BBS 2.36 ÀÌÀü ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ Á¶ÀÛµÈ À̹ÌÁö ÆÄÀÏ°ú °ü·ÃµÈ º¤Å͸¦ ÅëÇØ ÀÓÀÇÀÇ HTML ¹®¼¸¦ ¾÷·Îµå ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
3. CVE-2015-4287
Firepower 9000 ±â±âÀÇ Cisco Firepower Extensible Operating System 1.1(1.86) ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼ ¸í½ÃµÇÁö ¾ÊÀº À¥ ÆäÀÌÁö ¹æ¹®À» ÅëÇØ ÀǵµµÈ Á¢¼Ó Á¦ÇÑÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁÖ°í ¹Î°¨ÇÑ ±â±â Á¤º¸¸¦ Å»ÃëÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. ÀÌ´Â Bug ID CSCuu82230°ú µ¿ÀÏÇÕ´Ï´Ù.
4. CVE-2015-4288
Cisco WSA 8.5.0-000 ¹öÀü, ESA 8.5.7-042 ¹öÀü, SMA 8.3.6-048 ¹öÀüÀÇ LDAP ±¸Çö¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ Áß°£ÀÚ°ø°ÝÀ¸·Î ¸í½ÃµÇÁö ¾ÊÀº º¤Å͸¦ ÅëÇØ ¼¹ö¸¦ ½ºÇªÇÁ ½ÃÄÑÁÖ°í ¹Î°¨ÇÑ Á¤º¸¸¦ Å»ÃëÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù.
Copyrighted 2015. UBM-Tech. 117153:0515BC
[±¹Á¦ºÎ ÁÖ¼ÒÇü ±âÀÚ(sochu@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>