[º¸¾È´º½º ±è°æ¾Ö] ½Ã½ºÄÚ(Cisco)°¡ ASA ¼ÒÇÁÆ®¿þ¾î¿¡ ¿µÇâÀ» ÁÖ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
¡ã º¸¾È ¾÷µ¥ÀÌÆ® °øÁö(Ãâó: ½Ã½ºÄÚ)
ÇØ´ç Ãë¾àÁ¡Àº ½Ã½ºÄÚ ASA ¼ÒÇÁÆ®¿þ¾îÀÇ IKEv1 ¹× IKEv2¿¡¼ Á¶ÀÛµÈ UDP ÆÐŶÀ» ó¸®ÇÒ ¶§ ÀÓÀÇÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2016-1287)ÀÌ´Ù.
¿µÇâÀ» ¹Þ´Â Á¦Ç°Àº Âü°í»çÀÌÆ®¿¡ ¸í½ÃµÇ¾î ÀÖ´Â ¡®Affected Products¡¯À» ÅëÇØ Ãë¾àÇÑ Á¦Ç°À» È®ÀÎÇØ¾ß ÇÑ´Ù.
µû¶ó¼ ÀÌ¿ëÀÚ´Â Ãë¾àÁ¡ÀÌ ¹ß»ýÇÑ ½Ã½ºÄÚ ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÈ ½Ã½ºÄÚ ÀåºñÀÇ ¿î¿µÀÚ´Â ÇØ´çµÇ´Â Âü°í»çÀÌÆ®¿¡ ¸í½ÃµÇ¾î ÀÖ´Â ¡®Affected Products¡¯ ¹× ¡®Obtaining Fixed Software¡¯ ³»¿ëÀ» È®ÀÎÇØ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.
Á»´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ¿¡ ¹®ÀÇ(±¹¹ø¾øÀÌ 118)ÇÏ¸é µÈ´Ù.
[¿ë¾î ¼³¸í]
ASA(Adaptive Security Appliance) ¼ÒÇÁÆ®¿þ¾î: ½Ã½ºÄڻ翡¼ Á¦ÀÛÇÑ ³×Æ®¿öÅ© º¸¾È Ç÷§Æû
[Âü°í»çÀÌÆ®]
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>