¿µÇâ¹Þ´Â »ç¿ëÀÚ, ÃֽŠ¹öÀüÀ¸·Î ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÏ°í ¾÷µ¥ÀÌÆ®Çؾß
[º¸¾È´º½º ±è°æ¾Ö] VMware°¡ Ŭ¶óÀ̾ðÆ® ÅëÇÕ Ç÷¯±×Àο¡¼ÀÇ º¸¾ÈÃë¾àÁ¡À» º¸¿ÏÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
ÇØ´ç Ãë¾àÁ¡Àº Vmware vSphere Web Client ÀÌ¿ëÀÚ°¡ ¾Ç¼º À¥ »çÀÌÆ® ¹æ¹®½Ã Ŭ¶óÀ̾ðÆ® ÅëÇÕ Ç÷¯±×Àο¡¼ ¼¼¼Ç °ü¸® ¹ÌÈíÀ¸·Î ÀÎÇØ Áß°£ÀÚ °ø°Ý(MiTM)À̳ª À¥ ¼¼¼Ç ÇÏÀÌÀçÅ·ÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2016-2076)ÀÌ´Ù.
¿µÇâÀ» ¹Þ´Â ¹öÀüÀº ´ÙÀ½°ú °°´Ù.
ÇöÀç Ãë¾àÇÑ ¹öÀüÀÇ CIP(Client Integration Plugin)¿¡´Â vCloud Director 8.0.0Àº žÀçµÇ¾î ÀÖÁö ¾ÊÀ¸³ª, CIP ÃֽŠ¹öÀü¿¡´Â vCloud Director 8.0.1ÀÌ Å¾ÀçµÅ ÀÖ´Ù.
µû¶ó¼ vCenter Server, vCloud Director, vRealize Automation Identity Appliance¿¡ ´ëÇØ ¿µÇâ ¹Þ´Â ¹öÀü »ç¿ëÀÚÀÇ °æ¿ì, ¾Æ·¡ ¸µÅ©¿¡¼ °¢°¢ ÃֽŠ¹öÀüÀ» ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
- vCenter Server: https://www.vmware.com/go/download-vsphere
- vCloud Director 5.5.6: https://www.vmware.com/go/download/vcloud-director
- VMware vRealize Automation 6.2.4.1:
https://my.vmware.com/web/vmware/info/slug/infrastructure_operations
_management/vmware_vrealize_automation/6_2
¶ÇÇÑ, vSphere Web Cleint°¡ ÀÌ¿ëµÇ´Â ½Ã½ºÅÛÀÇ Å¬¶óÀ̾ðÆ® ÅëÇÕ Ç÷¯±×ÀÎÀ» ¾÷µ¥ÀÌÆ®¸¦ ÇØ¾ß ÇÑ´Ù.
Á» ´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)¸¦ Âü°íÇÏ¸é µÈ´Ù.
[¿ë¾î ¼³¸í]
MITM(Man-In-The-Middle) °ø°Ý: Åë½ÅÇÏ°í ÀÖ´Â µÎ ´ç»çÀÚ »çÀÌ¿¡ ³¢¾îµé¾î ±³È¯ÇÏ´Â Á¤º¸¸¦ Àڱ⠰Ͱú ¹Ù²Ù¾î¹ö¸²À¸·Î½á µéÅ°Áö ¾Ê°í µµÃ»À» Çϰųª Åë½Å ³»¿ëÀ» ¹Ù²Ù´Â ÇØÅ· ±â¹ý
[Âü°í»çÀÌÆ®]
http://www.vmware.com/security/advisories/VMSA-2016-0004.html
https://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=2145066
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2076
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>