ÄݵåÇ»Àü¿¡¼ ¹ß»ýÇÒ ¼ö ÀÖ´Â Á¤º¸³ëÃâ Ãë¾àÁ¡, ÆÐÄ¡ÇÏ¸é ¾ÈÀü
[º¸¾È´º½º ¹Î¼¼¾Æ] ¾îµµºñ(Adobe)»ç´Â ÄݵåÇ»Àü(ColdFusion)¿¡¼ ¹ß»ýÇÒ ¼ö ÀÖ´Â Á¤º¸³ëÃâ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
ÇØ´ç Ãë¾àÁ¡Àº ¡âÄݵåÇ»Àü 11°ú ¡âÄݵåÇ»Àü 10 »ç¿ëÀÚ°¡ Á¶ÀÛµÈ XML External Entities ó¸® ½Ã ÁÖ¿ä Á¤º¸°¡ ³ëÃâµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2015-3269)ÀÌ´Ù.
ÄݵåÇ»Àü 11 »ç¿ëÀÚ´Â ColdFusion 11 Update 6 ÆäÀÌÁö¿¡, ÄݵåÇ»Àü 10 »ç¿ëÀÚ´Â ColdFusion 11 Update 17 ÆäÀÌÁö¿¡¼ ÇÖÇȽº¸¦ ¼³Ä¡ÇØ Ãë¾àÁ¡À» ÇØ°áÇÒ ¼ö ÀÖ´Ù.
º¸´Ù ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
https://helpx.adobe.com/security/products/coldfusion/apsb15-21.html
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>