CVE-2015-8650, CVE-2015-8651
[º¸¾È´º½º ¹®°¡¿ë] ÇöÁö ½Ã°¢À¸·Î 12¿ù 28ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 28ÀÏ¿¡¼ 29ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2015-8647
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î 18.0.0.324 ÀÌÀü ¹öÀü°ú 20.0.0.267 ÀÌÀüÀÇ 19.x / 20.x ¹öÀü(À©µµ¿ì¿ë/OS X¿ë)°ú 11.2.202.559 ÀÌÀü ¹öÀü(¸®´ª½º¿ë), ¾îµµºñ AIR 20.0.0.233 ÀÌÀü ¹öÀü, ¾îµµºñ AIR SDK 20.0.0.233 ÀÌÀü ¹öÀü, Adobe AIR SDK & Compiler 20.0.0.233 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Use-after-free Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤µÇÁö ¾ÊÀº °æ·Î¸¦ ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650°ú´Â ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
2. CVE-2015-8648
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î 18.0.0.324 ÀÌÀü ¹öÀü°ú 20.0.0.267 ÀÌÀüÀÇ 19.x / 20.x ¹öÀü(À©µµ¿ì¿ë/OS X¿ë)°ú 11.2.202.559 ÀÌÀü ¹öÀü(¸®´ª½º¿ë), ¾îµµºñ AIR 20.0.0.233 ÀÌÀü ¹öÀü, ¾îµµºñ AIR SDK 20.0.0.233 ÀÌÀü ¹öÀü, Adobe AIR SDK & Compiler 20.0.0.233 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Use-after-free Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤µÇÁö ¾ÊÀº °æ·Î¸¦ ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650°ú´Â ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2015-8649
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î 18.0.0.324 ÀÌÀü ¹öÀü°ú 20.0.0.267 ÀÌÀüÀÇ 19.x / 20.x ¹öÀü(À©µµ¿ì¿ë/OS X¿ë)°ú 11.2.202.559 ÀÌÀü ¹öÀü(¸®´ª½º¿ë), ¾îµµºñ AIR 20.0.0.233 ÀÌÀü ¹öÀü, ¾îµµºñ AIR SDK 20.0.0.233 ÀÌÀü ¹öÀü, Adobe AIR SDK & Compiler 20.0.0.233 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Use-after-free Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤µÇÁö ¾ÊÀº °æ·Î¸¦ ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8650°ú´Â ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
4. CVE-2015-8650
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î 18.0.0.324 ÀÌÀü ¹öÀü°ú 20.0.0.267 ÀÌÀüÀÇ 19.x / 20.x ¹öÀü(À©µµ¿ì¿ë/OS X¿ë)°ú 11.2.202.559 ÀÌÀü ¹öÀü(¸®´ª½º¿ë), ¾îµµºñ AIR 20.0.0.233 ÀÌÀü ¹öÀü, ¾îµµºñ AIR SDK 20.0.0.233 ÀÌÀü ¹öÀü, Adobe AIR SDK & Compiler 20.0.0.233 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Use-after-free Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤µÇÁö ¾ÊÀº °æ·Î¸¦ ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649¿Í´Â ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
5. CVE-2015-8651
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î 18.0.0.324 ÀÌÀü ¹öÀü°ú 20.0.0.267 ÀÌÀüÀÇ 19.x / 20.x ¹öÀü(À©µµ¿ì¿ë/OS X¿ë)°ú 11.2.202.559 ÀÌÀü ¹öÀü(¸®´ª½º¿ë), ¾îµµºñ AIR 20.0.0.233 ÀÌÀü ¹öÀü, ¾îµµºñ AIR SDK 20.0.0.233 ÀÌÀü ¹öÀü, Adobe AIR SDK & Compiler 20.0.0.233 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Á¤¼ö ¿À¹öÇ÷οì Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤µÇÁö ¾ÊÀº °æ·Î¸¦ ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>