CVE-2016-9294, CVE-2016-9296
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 11¿ù 11ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 11ÀÏ¿¡¼ 12ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-9285
Exponent CMS v2.4.0 ¹öÀüÀÇ framework/modules/addressbook/controllers/addressController.phpÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ »ç¿ëÀÚ Á¤º¸¸¦ ÀоîµéÀÏ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2016-9286
Exponent CMS v2.4.0patch1 ¹öÀüÀÇ framework/modules/users/controllers/usersController.phpÀÇ Ãë¾àÁ¡À¸·Î »ç¿ëÀÚ ±â·Ï¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦´ë·Î ¸·Áö ¾Ê´Â´Ù. ÀÌ·Î½á ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ ÁÖ¼Ò Á¤º¸¸¦ ÀоîµéÀÏ ¼ö ÀÖ°Ô µÈ´Ù.
3. CVE-2016-9288
Exponent CMS v2.4.0°ú ±× ÀÌÀü ¹öÀüÀÇ framework/modules/navigation/controllers/navigationController.phpÀÇ Ãë¾àÁ¡À¸·Î DragnDropReRank ÇÔ¼öÀÇ targetÀ̶ó´Â ¸Å°³º¯¼ö°¡ SQL ÀÎÁ§¼Ç¿¡ È°¿ëµÉ ¼ö ÀÖ´Ù.
4. CVE-2016-9294
Artifex Software, Inc. MuJS 5008105780c0b0182ea6eda83ad5598f225be3ee ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ malformed labeled break/continue in JavaScript Á¢±ÙÀ» ÅëÇØ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. NULL pointer dereference¿Í °ü·ÃÀÌ ÀÖ´Ù.
5. CVE-2016-9296
p7zip 16.02°ú ¿©·¯ ´Ù¸¥ ÀÌÀü ¹öÀüÀÇ null pointer dereference ¹ö±×·Î malformed 7z ÆÄÀϵéÀ» µðÄÚµùÇÒ ¶§ ½Ã½ºÅÛ Å©·¡½Ã³ª DoS °ø°Ý °¡´É¼ºÀÌ ¹ß»ýÇÑ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>