CVE-2016-1702, CVE-2016-1703
[º¸¾È´º½º ¹®°¡¿ë] ÇöÁö ½Ã°¢À¸·Î 6¿ù 5ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 5ÀÏ¿¡¼ 6ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-1700
±¸±Û Å©·Ò 51.0.2704.79 ÀÌÀü ¹öÀüÀÇ extensions/renderer/runtime_custom_bindings.cc ³»¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î extension viewsÀÇ ¾î·¹À̸¦ ¸¸µé ¶§ ºÎÀÛ¿ëÀÌ ¹ß»ýÇÑ´Ù. ÀÌ·Î½á ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ extension°ú °ü·ÃµÈ ¹æ¹ýÀ¸·Î DoS °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
2. CVE-2016-1701
±¸±Û Å©·Ò 51.0.2704.79 ÀÌÀü ¹öÀüÀÇ Autofill¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î field update¿Í ÇÁ·¹ÀÓ »èÁ¦ ±â´ÉÀ» °¡Áö°í ÀÖ´Â ÀÚ¹Ù½ºÅ©¸³Æ® ÄÚµå »çÀÌÀÇ »óÈ£ÀÛ¿ëÀ» À߸ø ó¸®ÇÑ´Ù. ÀÌ·Î½á ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Á¶ÀÛµÈ À¥ »çÀÌÆ®¸¦ ÅëÇÏ¿© DoS °ø°ÝÀ» ÇÏ´Â °Ô °¡´ÉÇÏ´Ù. CVE-2016-1690°ú ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2016-1702
±¸±Û Å©·Ò 51.0.2704.79 ÀÌÀü ¹öÀüÀÇ SkiaÀÇ core/SkRegion.cppÀÇ SkRegion::readFromMemory ÇÔ¼ö¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ³»ºÎ Ä«¿îÆ®¸¦ È®ÀÎÇÏÁö ¾Ê´Â´Ù. ÀÌ·Î½á ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ Á¶ÀÛµÈ ½Ã¿¬¼Ó µ¥ÀÌÅ͸¦ ÅëÇÏ¿© DoS °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2016-1703
±¸±Û Å©·Ò 51.0.2704.79 ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡µé·Î °ø°ÝÀÚ°¡ DoS °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>
- ±¹³» ÃÖ´ë ±Ô¸ðÀÇ °³ÀÎÁ¤º¸º¸È£ ÄÁÆÛ·±½º PIS FAIR 2016 - 6¿ù 9ÀÏ(¸ñ)~10ÀÏ(±Ý) °³ÃÖ- °ø°ø¡¤±ÝÀ¶¡¤¹Î°£ CPO, °³ÀÎÁ¤º¸Ã³¸®ÀÚ, º¸¾È´ã´çÀÚ µî 4,000¿©¸í Âü¼®
- °ø¹«¿ø»ó½ÃÇнÀ, CPPG, CISSP, CISA µî °ü·Ã ±³À°À̼ö(ÃÖ´ë 16½Ã°£) ÀÎÁ¤
- CPO, °³ÀÎÁ¤º¸Ã³¸®ÀÚ, º¸¾È´ã´çÀÚ µî »çÀü ¹«·á Âü°üµî·Ï(www.pisfair.org/2016/)