CVE-2016-6536, CVE-2016-6537
1. CVE-2016-5814
Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, RSLogix 500 Professional EdtionÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ RSS ÆÄÀÏÀ» ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2016-6415
½Ã½ºÄÚ IOS 12.1~12.4 ¹öÀü, 15.0~15.6 ¹öÀü, IOS XE~3.18S ¹öÀü, IOS XR 4.3.x ¹öÀü°ú 5.0.x~5.2.x ¹öÀü, PIX 7.0 ÀÌÀü ¹öÀüÀÇ ¼¹ö IKEv1 µµÀÔ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ±â±â ¸Þ¸ð¸®¸¦ ÅëÇØ ¹Î°¨ÇÑ Á¤º¸¸¦ ÃëµæÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Bug ID CSCvb29204, CSCvb36055, BENIGNCERTAIN°ú µ¿ÀÏÇÏ´Ù.
3. CVE-2016-6535
Æß¿þ¾î X9.03.24.00.071ÀÏ ¼³Ä¡µÈ AVer Information EH6108H+ ±â±âµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î °èÁ¤µéÀÌ ÇϵåÄÚµù µÇ¾î ÀÖ´Ù. ÀÌ·Î½á ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ ·çÆ® Á¢±Ù ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
4. CVE-2016-6536
Æß¿þ¾î X9.03.24.00.071ÀÏ ¼³Ä¡µÈ AVer Information EH6108H+ÀÇ /setup URI¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀǵµµÈ ÆäÀÌÁö Á¢±Ù ÀåÄ¡¸¦ ¿ìȸÇϰųª ¾ÏÈ£¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2016-6537
Æß¿þ¾î X9.03.24.00.071ÀÏ ¼³Ä¡µÈ AVer Information EH6108H+ ±â±âµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¾ÏÈ£¸¦ Æò¹® base64 Æ÷¸ËÀ¸·Î ÀúÀåÇÏ°í HTTP ÄíÅ° Çì´õ¿¡ Æò¹® Å©¸®µ§¼ÈÀ» ¿äûÇÑ´Ù. ÀÌ·Î½á °ø°ÝÀÚµéÀÌ ¹Î°¨ÇÑ Á¤º¸¸¦ ÃëµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>