CVE-2016-3680, CVE-2016-3681
1. CVE-2015-7360
Fortinet FortiSandbox 2.1 ÀÌÀü ¹öÀüÀÇ Web User InterfaceÀÇ ´Ù¼ö XSS Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ alerts/summary/profile/¿¡ÀÇ ½Ã¸®¾ó ¸Å°³º¯¼ö, csearch/report/export/¿¡ÀÇ urlForCreatingReport ¸Å°³º¯¼ö, analysis/detail/download/screenshot¿¡ÀÇ id ¸Å°³º¯¼ö µîÀ» ÅëÇÏ¿© ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2016-1385
½Ã½ºÄÚ Adaptive Security Appliance ¼ÒÇÁÆ®¿þ¾î 9.5.2 ¹öÀüÀÇ XML Æļ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ °ü¸®ÀÚ Á¢±Ù, Clienetless SSL VPN Á¢±ÙÀ» ÅëÇÏ¿© DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Bug ID CSCut14209¿Í µ¿ÀÏÇÏ´Ù.
3. CVE-2016-0718
ExpatÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ À߸øµÈ input ¹®¼¸¦ ÅëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϰųª DoS °ø°ÝÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2016-3680
Huawei Mate 8 NXT-AL10C00B182 ÀÌÀü ¹öÀüÀÇ NXT-AL, NXT-CL00C92B182 ÀÌÀü ¹öÀüÀÇ NXT-CL, NXT-DL00C17B182 ÀÌÀü ¹öÀüÀÇ NXT-DL, NXT-TL00C01B182 ÀÌÀü ¹öÀüÀÇ NXT-TL¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î °ø°ÝÀÚµéÀÌ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2016-3681
Huawei Mate 8 NXT-AL10C00B182 ÀÌÀü ¹öÀüÀÇ NXT-AL, NXT-CL00C92B182 ÀÌÀü ¹öÀüÀÇ NXT-CL, NXT-DL00C17B182 ÀÌÀü ¹öÀüÀÇ NXT-DL, NXT-TL00C01B182 ÀÌÀü ¹öÀüÀÇ NXT-TLÀÇ ¿ÍÀÌÆÄÀÌ µå¶óÀ̹ö¿¡ ÀÖ´Â ¹öÆÛ¿À¹öÇ÷οì Ãë¾àÁ¡À¸·Î °ø°ÝÀÚµéÀÌ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>
- ±¹³» ÃÖ´ë ±Ô¸ðÀÇ °³ÀÎÁ¤º¸º¸È£ ÄÁÆÛ·±½º PIS FAIR 2016 - 6¿ù 9ÀÏ(¸ñ)~10ÀÏ(±Ý) °³ÃÖ- °ø°ø¡¤±ÝÀ¶¡¤¹Î°£ CPO, °³ÀÎÁ¤º¸Ã³¸®ÀÚ, º¸¾È´ã´çÀÚ µî 4,000¿©¸í Âü¼®
- °ø¹«¿ø»ó½ÃÇнÀ, CPPG, CISSP, CISA, ISMSµî °ü·Ã ±³À°À̼ö(ÃÖ´ë 16½Ã°£) ÀÎÁ¤
- CPO, °³ÀÎÁ¤º¸Ã³¸®ÀÚ, º¸¾È´ã´çÀÚ µî »çÀü ¹«·á Âü°üµî·Ï(www.pisfair.org/2016/)