CVE-2016-5303, CVE-2016-9757
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 12¿ù 20ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 20ÀÏ¿¡¼ 21ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
1. CVE-2016-7298
MS Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011, Office 2016 for MacÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϰųª DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. Microsoft Office Memory Corruption Vulnerability¶ó°í ºÒ¸®±âµµ ÇÑ´Ù.
2. CVE-2016-7300
MS Auto Updater for MacÀÇ °Ë»ö °æ·Î ½Å·Ú Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ ¾Ç¼º ½ÇÇà ÆÄÀÏÀ» ÅëÇØ ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ´Ù. Microsoft Office Elevation of Privilege Vulnerability¶ó°íµµ ºÒ¸°´Ù.
3. CVE-2016-4552
Roundcube Webmail 1.2.0 ÀÌÀü ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
4. CVE-2016-5303
Horde Groupware / Horde Groupware Webmail Edition 5.2.16 ÀÌÀü ¹öÀüÀÇ Horde Text Filter APIÀÇ XSS Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ actionÀ̳ª xlink ÄÜÅÙÃ÷ ÆûÀ» ÅëÇÏ¿© ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
5. CVE-2016-9757
Rapid7 Nexpose 6.4.12 ¹öÀü »ç¿ëÀÚ ÀÎÅÍÆäÀ̽ºÀÇ Create Tags ÆäÀÌÁöÀÇ Ãë¾àÁ¡À¸·Î ÀÎÁõµÈ »ç¿ëÀÚ°¡ XSS ¿ä¼ÒµéÀ» ÅÂ±× À̸§ Çʵ忡 ÁÖÀÔÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>