[º¸¾È´º½º ¹Î¼¼¾Æ] ¾îµµºñ(Adobe)»ç´Â Ç÷¡½Ã Ç÷¹À̾î(Flash Player)¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù. ³·Àº ¹öÀü »ç¿ëÀÚ´Â ¾Ç¼ºÄÚµå °¨¿°¿¡ Ãë¾àÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÇØ°á¹æ¾È¿¡ µû¶ó ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ´Â °ÍÀÌ ¾ÈÀüÇÏ´Ù.
¹ßÇ¥µÈ º¸¾È ¾÷µ¥ÀÌÆ®´Â ¾îµµºñ Ç÷¡½Ã Ç÷¹À̾îÀÇ 26°³ Ãë¾àÁ¡¿¡ ´ëÇÑ °ÍÀ¸·Î, ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Á¤¼ö ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2016-4287) ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â Use-Ater-Free Ãë¾àÁ¡(CVE-2016-4272, CVE-2016-4279, CVE-2016-6921, CVE-2016-6923, CVE-2016-6925, CVE-2016-6926, CVE-2016-6927, CVE-2016-6929, CVE-2016-6930, CVE-2016-6931, CVE-2016-6932) ¡âÁ¤º¸ ³ëÃâ·Î À̾î Áú ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2016-4271, CVE-2016-4277, CVE-2016-4278) ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡(CVE-2016-4274, CVE-2016-4275, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4283, CVE-2016-4284, CVE-2016-4285, CVE-2016-6922, CVE-2016-6924) µîÀÌ´Ù.
¡ã¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
ÀÌ¿¡ µû¶ó À©µµ¿ìÁî, ¸Æ ȯ°æÀÇ Adobe Flash Player desktop runtime »ç¿ëÀÚ´Â 23.0.0.162 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ëÇϰųª Adobe Flash Player Download Center(http://www.adobe.com/go/getflash)¿¡ ¹æ¹®ÇØ ÃֽŠ¹öÀüÀ» ¼³Ä¡ ¹× ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ÀÌ¿ëÇØ ¾÷±×·¹À̵带 ÇÏ¸é µÈ´Ù.
¶ÇÇÑ, Adobe Flash Player Extended Support Release »ç¿ëÀÚ´Â 18.0.0.375 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ°í, Windows 10 ¹× Windows 8.1¿¡¼ ±¸±Û Å©·Ò, Microsoft Edge, ÀÎÅÍ³Ý ÀͽºÇ÷η¯¿¡ Adobe Flash Player¸¦ ¼³Ä¡ÇÑ »ç¿ëÀÚ´Â ÀÚµ¿À¸·Î ÃֽŠ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ´Ù.
±× ¿Ü »ç¿ëÀÚ´Â Adobe Flash Player Download Center(http://www.adobe.com/go/getflash)¿¡ ¹æ¹®ÇØ ÃֽŠ¹öÀüÀ» ¼³Ä¡ÇÏ¸é µÈ´Ù. Adobe AIR SDK¿Í AIR SDK & Compiler »ç¿ëÀÚ´Â 23.0.0.257 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ°í, http://www.adobe.com/devnet/air/air-sdk-download.html¿¡ ¹æ¹®ÇÏ¿© ÃֽŠ¹öÀüÀ» ¼³Ä¡ÇÏ¸é µÈ´Ù. ¸®´ª½º ȯ°æÀÇ Adobe Flash Player »ç¿ëÀÚ´Â 11.2.202.635 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ¸é µÈ´Ù.
º¸´Ù ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
1. https://helpx.adobe.com/security/products/flash-player/apsb16-29.html
2. https://helpx.adobe.com/security/products/air/apsb16-31.html
[¿ë¾î Á¤¸®]
Use-After-Free Ãë¾àÁ¡ : ¼ÒÇÁÆ®¿þ¾î ±¸Çö ½Ã µ¿Àû ȤÀº Á¤ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸®¸¦ ÇØÁ¦ÇßÀ½¿¡µµ ºÒ±¸ÇÏ°í À̸¦ °è¼Ó ÂüÁ¶(»ç¿ë)ÇÏ¿© ¹ß»ýÇÏ´Â Ãë¾àÁ¡
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>