[º¸¾È´º½º ¹Î¼¼¾Æ] ¾îµµºñ(Adobe)´Â Ç÷¡½Ã Ç÷¹À̾î(Flash Player)¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù.
ÇØ´ç º¸¾È ¾÷µ¥ÀÌÆ®´Â ÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Type Confusion Ãë¾àÁ¡°ú Use-After-Free Ãë¾àÁ¡ µîÀ» Æ÷ÇÔÇÑ 36°³ Ãë¾àÁ¡¿¡ ´ëÇÑ ¾÷µ¥ÀÌÆ®´Ù.
³·Àº ¹öÀü »ç¿ëÀÚ´Â ¾Ç¼ºÄÚµå °¨¿°¿¡ Ãë¾àÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÇØ°á¹æ¾È¿¡ µû¶ó ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ´Â °ÍÀÌ ¾ÈÀüÇÏ´Ù.
[º¸¾È Ãë¾àÁ¡ »ó¼¼ ¸ñ·Ï]
- ÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Type confusion Ãë¾àÁ¡(CVE-2016-4144, CVE-2016-4149)
- ÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Use-Ater-Free Ãë¾àÁ¡(CVE-2016-4142, CVE-2016-4143, CVE-2016-4145, CVE-2016-4146, CVE-2016-4147, CVE-2016-4148)
- ÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Èü ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2016-4135, CVE-2016-4136, CVE-2016-4138)
- ÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡(CVE-2016-4122, CVE-2016-4123, CVE-2016-4124, CVE-2016-4125, CVE-2016-4127, CVE-2016-4128, CVE-2016-4129, CVE-2016-4130, CVE-2016-4131, CVE-2016-4132, CVE-2016-4133, CVE-2016-4134, CVE-2016-4137, CVE-2016-4141, CVE-2016-4150, CVE-2016-4151, CVE-2016-4152, CVE-2016-4153, CVE-2016-4154, CVE-2016-4155, CVE-2016-4156, CVE-2016-4166, CVE-2016-4171)
- µð·ºÅ丮 °Ë»ö °æ·Î°¡ Ãë¾àÇÏ¿© ÀÓÀÇÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2016-4140)
- same-origin-policy ¿ìȸ ¹× Á¤º¸ ´©Ãâ Ãë¾àÁ¡(CVE-2016-4139)
¡ã¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
ÀÌ¿¡ µû¶ó À©µµ¿ìÁî, ¸Æ ȯ°æÀÇ ¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î desktop runtime »ç¿ëÀÚ´Â 22.0.0.192 ¹öÀüÀ¸·Î, Extended Support Release »ç¿ëÀÚ´Â 18.0.0.360 ¹öÀüÀ¸·Î, ¸®´ª½º ȯ°æÀÇ Adobe Flash Player »ç¿ëÀÚ´Â 11.2.202.626 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¸é µÈ´Ù.
À©µµ¿ìÁî(Windows) 10 ¹× À©µµ¿ìÁî 8.1¿¡¼ ±¸±Û Å©·Ò, ¸¶ÀÌÅ©·Î dptÁö(Microsoft Edge), ÀÎÅÍ³Ý ÀͽºÇ÷η¯(IE)¿¡ ¾îµµºñ Ç÷¡½Ã Ç÷¹À̾ ¼³Ä¡ÇÑ »ç¿ëÀÚ´Â ÀÚµ¿À¸·Î ÃֽŠ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ´Ù. ±× ¿Ü »ç¿ëÀÚ´Â Adobe Flash Player Download Center(http://www.adobe.com/go/getflash)¿¡ ¹æ¹®ÇØ ÃֽŠ¹öÀüÀ» ¼³Ä¡ÇÏ¸é µÈ´Ù.
ÀÌ¿Í °ü·ÃÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
[¿ë¾î Á¤¸®]
Use-After-Free Ãë¾àÁ¡ : ¼ÒÇÁÆ®¿þ¾î ±¸Çö ½Ã µ¿Àû ȤÀº Á¤ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸®¸¦ ÇØÁ¦ÇßÀ½¿¡µµ ºÒ±¸ÇÏ°í À̸¦ °è¼Ó ÂüÁ¶(»ç¿ë)ÇØ ¹ß»ýÇÏ´Â Ãë¾àÁ¡
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>