CVE-2016-2003, CVE-2016-2202
[º¸¾È´º½º ¹®°¡¿ë] ÇöÁö ½Ã°¢À¸·Î 4¿ù 20ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 20ÀÏ¿¡¼ 21ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-0891
EMC ViPR SRM 3.7 ÀÌÀü ¹öÀüÀÇ °ü¸®ÀÚ ÆäÀÌÁö¿¡ ÀÖ´Â CSRF Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÎÁõ ´Ü°è¸¦ ÇÏÀÌÀçÅ· ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2016-1384
Cisco IOS 15.1°ú 15.5, IOS XE 3.2~3.17 ¹öÀüÀÇ NTP implementation¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ÆÐŶÀ» ÅëÇØ ½Ã½ºÅÛ ½Ã°£À» Á¶ÀÛÇÒ ¼ö ÀÖ°Ô µÈ´Ù. Bug ID CSCux46898°ú µ¿ÀÏÇÏ´Ù.
3. CVE-2016-2002
HPE Vertica 7.0.2.12 ÀÌÀüÀÇ 7.0.x ¹öÀü, 7.1.2-12 ÀÌÀüÀÇ 7.1.x ¹öÀü, 7.2.2-1 ÀÌÀüÀÇ 7.2.x ¹öÀüÀÇ Analytics Management ConsoleÀÇ validateAdminConfig handler¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ mcPort ¸Å°³º¯¼ö¸¦ ÅëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. ZDI-CAN-3417°ú µ¿ÀÏÇÏ´Ù.
4. CVE-2016-2003
HPE P9000 Command View Advanced Edition Software(CVAE) 7.x¿Í 8.4.0-00 ÀÌÀüÀÇ 8.x ¹öÀü, XP7 CVAE 7.x¿Í 8.4.0-00 ÀÌÀüÀÇ 8.x ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ ÀÚ¹Ù °´Ã¼¸¦ ÅëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Apache Commons Collections ¶óÀ̺귯¸®¿Í ¿¬°üÀÌ ÀÖ´Ù.
5. CVE-2016-2202
Symantec Altiris IT Management Suite(ITMS) 7.6HF7 ¹öÀüÀÇ Management AgentÀÇ Inventory Solution¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ·ÎÄà »ç¿ëÀÚ°¡ ¾ÖÇø®ÄÉÀÌ¼Ç ºí·¢¸®½ºÆ® Á¦ÇÑ ±â´ÉÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>