CVE-2016-3115, CVE-2016-3116
1. CVE-2015-7454
IBM WebSphere Process Server 6.1.2.0¿¡¼ 7.0.0.5 ¹öÀü, Business Process Manager Advanced 7.5.x¿¡¼ 7.5.1.2 ¹öÀü, 8.0.x¿¡¼ 8.0.1.3 ¹öÀü, 8.5.0.x¿¡¼ 8.5.0.2 ¹öÀü, 8.5.5.x¿¡¼ 8.5.5.0 ¹öÀü, 8.5.6.x¿¡¼ 8.5.6.2 ¹öÀü¿¡ ÀÖ´Â Business Space¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ Á¢±Ù Á¦ÇÑ ±â´ÉÀ» ¿ìȸÇØ ÀÓÀÇÀÇ ÆäÀÌÁö¸¦ »ý¼ºÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
2. CVE-2016-1997
HPE Operations Orchestration 10.51 ÀÌÀüÀÇ 10.x ¹öÀü, Operations Orchestration ÄÜÅÙÆ® 1.7.0 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ÀÚ¹Ù °´Ã¼¸¦ ÅëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Apache Commons Collections ¶óÀ̺귯¸®¿Í °ü·ÃÀÌ ÀÖ´Ù.
3. CVE-2016-1998
HPE Service Manager(SM) 9.35 P4 ÀÌÀüÀÇ 9.3x ¹öÀü°ú 9.41.P2 ÀÌÀüÀÇ 9.4x ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ÀÚ¹Ù °´Ã¼¸¦ ÅëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. Apache Commons Collections ¶óÀ̺귯¸®¿Í °ü·ÃÀÌ ÀÖ´Ù.
4. CVE-2016-3115
OpenSSH 7.2p2 ÀÌÀü ¹öÀüÀÇ sshdÀÇ session.c¿¡ ÀÖ´Â ´Ù·®ÀÇ CRLF ÀÎÁ§¼Ç Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ Á¶ÀÛµÈ X11 Æ÷¿öµù µ¥ÀÌÅ͸¦ ÅëÇØ ÀǵµµÈ ½© ¸í·É¾î Á¦ÇÑ ±â´ÉÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. do_authenticated1¿Í session_x11_req ÇÔ¼ö¿Í °ü·ÃÀÌ ÀÖ´Ù.
5. CVE-2016-3116
Dropbear SSH 2016.72 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â CRLF ÀÎÁ§¼Ç Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ Á¶ÀÛµÈ X11 Æ÷¿öµù µ¥ÀÌÅ͸¦ ÅëÇØ ÀǵµµÈ ½© ¸í·É¾î Á¦ÇÑ ±â´ÉÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>