CVE-2017-6823, CVE-2014-9645
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 3¿ù 12ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 12ÀÏ¿¡¼ 13ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù
1. CVE-2017-5626
OnePlus 3°ú 3T ¹öÀü¿¡ ¼³Ä¡µÈ OxygenOS 4.0.2 ÀÌÀü ¹öÀüÀÇ µÎ °¡Áö ¼û°ÜÁø fastbook oem ¸í·É¾î(4F500301/4F500302)ÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ bootloader¸¦ Àá±×°Å³ª Ç® ¼ö ÀÖ°Ô ÇØÁØ´Ù. ÀÌ ¶§¹®¿¡ Áö¼ÓÀûÀÎ ³ôÀº ±ÇÇÑÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇØÁø´Ù.
2. CVE-2017-6444
MikroTik Router hAP Lite 6.25 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ¿äûµÇÁö ¾ÊÀº TCP ACK ÆÐŶÀÇ º¸È£ ¸ÞÄ¿´ÏÁòÀÌ Á¸ÀçÇÏÁö ¾Ê´Â´Ù. ÀÌ ¶§¹®¿¡ ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ´Ù·®ÀÇ ACK ÆÐŶÀ» º¸³» DoS °ø°ÝÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô µÈ´Ù. °ø°ÝÀÌ ¸ØÃèÀ» ¶§, CPU »ç¿ë·®ÀÌ 100%°¡ µÇ°í, ¶ó¿ìÅÍÀÇ ÀçºÎÆÃÀÌ ¹Ýµå½Ã ÇÊ¿äÇÏ°Ô µÈ´Ù.
3. CVE-2017-6820
Roundcube 1.1.8 ¹öÀü°ú 1.2.4 ÀÌÀüÀÇ 1.2.x ¹öÀüÀÇ rcube_utils.phpÀÇ XSS Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ Á¶ÀÛµÈ CSS ÅäÅ« ½ÃÄö½º¸¦ ÅëÇØ °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
4. CVE-2017-6823
Fiyo CMS 2.0.6.1 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ½ÂÀÎµÈ »ç¿ëÀÚ°¡ dapur/ÀÇ Á¶ÀÛµÈ ·¹º§ ¸Å°³º¯¼ö¸¦ ÅëÇØ ³ôÀº ±ÇÇÑÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
5. CVE-2014-9645
BusyBox 1.23.0 ÀÌÀü ¹öÀüÀÇ modutils/modprobe.cÀÇ add_probe ÇÔ¼öÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚ°¡ ¸ðµâ À̸§À» Á¶ÀÛÇÏ¿© º¸¾È ¸ÞÄ¿´ÏÁòÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>
- ¾Æ½Ã¾Æ ÃÖ´ë ±Ô¸ðÀÇ Á¾ÇÕ º¸¾È Àü½Ãȸ SECON 2017 - 3¿ù 15ÀÏ(¼ö)~17ÀÏ(±Ý) °³ÃÖ
- IFSEC°ú BlackHat ÁÖ°ü»çÀÎ UBMÀÌ Á÷Á¢ ÅõÀÚÇÑ Çѱ¹ À¯ÀÏ Àü½Ãȸ
- ÇØ¿Ü º¸¾È ºÐ¾ß ¹ÙÀ̾îµé°ú 1:1 Àü¹® »ó´ã
- °¡»óÇö½Ç, ½ÉÆó¼Ò»ý¼ú, µå·Ð ÇØÅ·, 1ÀÎ °¡±¸ ¾ÈÀü üÇè µî ´Ù¾çÇÑ ÄÚ³Ê ¸¶·Ã