CVE-2017-11366, CVE-2017-12977
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 8¿ù 20ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 20ÀÏ¿¡¼ 21ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2017-12973
Nimbus JOSE+JWT 4.39 ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ºÎÀûÀýÇÑ HMACÀ» ŽÁöÇÑ ÈÄ Ã³¸® °úÁ¤¿¡ ¿À·ù°¡ ÀÖ´Ù. ÀÌ·Î½á °ø°ÝÀÚµéÀÌ padding oracle °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
2. CVE-2017-12974
Nimbus JOSE+JWT 4.36 ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ECKey ±¸Ãà ½Ã °ø°³µÈ x¿Í y ÁÂÇ¥°ªÀÌ Á¦´ë·Î º¸È£µÇÁö ¾Ê´Â´Ù. ÀÌ·Î½á °ø°ÝÀÚµéÀÌ Invalid Curve °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô µÈ´Ù.
3. CVE-2017-12976
git-annex 6.20170818 ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ssh URLÀ» ÅëÇØ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, CVE-2017-1000117¿Í °ü·ÃÀÌ ÀÖ´Ù.
4. CVE-2017-11366
Codiad 2.8.4 ÀÌÀü ¹öÀüÀÇ components/filemanager/class.filemanager.phpÀÇ Ãë¾àÁ¡À¸·Î ¿ø°Ý ¸í·É ½ÇÇàÀ» °¡´ÉÇÏ°Ô ÇØÁØ´Ù.
5. CVE-2017-12977
Web-Dorado Photo Gallery by WD Ç÷¯±×ÀÎ 1.3.51 ÀÌÀü ¹öÀüÀÇ SQL ÀÎÁ§¼Ç Ãë¾àÁ¡À¸·Î photo-gallery.phpÀÇ bwg_edit_tag()¿Í admin/controllers/BWGControllerTags_bwg.phpÀÇ edit_tag()¿Í °ü·ÃÀÌ ÀÖ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>