CVE-2017-12199, CVE-2017-12200
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 8¿ù 1ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 1ÀÏ¿¡¼ 2ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2017-12143
libquicktime 1.2.4 ¹öÀüÀÇ lqt_quicktime.cÀÇ quicktime_read_info ÇÔ¼öÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚµéÀÌ Á¶ÀÛµÈ ÆÄÀÏÀ» ÅëÇØ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2017-12144
ytnef 1.9.2 ¹öÀüÀÇ ytnef.cÀÇ TNEFFillMapi ÇÔ¼öÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚµéÀÌ Á¶ÀÛµÈ ÆÄÀÏÀ» ÅëÇØ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
3. CVE-2017-12145
libquicktime 1.2.4 ¹öÀüÀÇ ftyp.cÀÇ quicktime_read_ftyp ÇÔ¼öÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ DoS °ø°ÝÀ» ÅëÇØ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2017-12199
¿öµåÇÁ·¹½º¿ë Etoile Ultimate Product Catalog Ç÷¯±×ÀÎ 4.2.11 ¹öÀüÀÇ SQL ÀÎÁ§¼Ç Ãë¾àÁ¡À¸·Î ´ÙÀ½ wp-admin/admin-ajax.php POST ¾×¼Çµé¿¡¼ ¹ß°ßµÈ´Ù. catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, tags_update_order tag-list-item.
5. CVE-2017-12200
¿öµåÇÁ·¹½º¿ë Etoile Ultimate Product Catalog Ç÷¯±×ÀÎ 4.2.11 ¹öÀüÀÇ XSS Ãë¾àÁ¡ÀÌ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>