CVE-2017-1000493, CVE-2017-18017
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 1¿ù 2ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 2ÀÏ¿¡¼ 3ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2017-1000466
Invoice Ninja 3.8.1 ¹öÀüÀÇ Àκ¸À̽º ¸¸µé±â ÆäÀÌÁöÀÇ XSS Ãë¾àÁ¡À¸·Î DoS °ø°ÝÀ̳ª ÀÚ¹Ù½ºÅ©¸³Æ® ÄÚµå ½ÇÇà °ø°ÝÀÌ °¡´ÉÇÏ´Ù.
2. CVE-2017-1000491
Shiba markdown live preview ¾Û 1.1.0 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
3. CVE-2017-1000492
Leanote-desktop 2.5 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
4. CVE-2017-1000493
Rocket.Chat Server 0.59 ¹öÀü ¹× ±× ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ °ü¸®ÀÚ ±ÇÇÑ ¹× °èÁ¤¿¡ ´ëÇÑ ÅëÁ¦±ÇÀ» °¡Á®°¥ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2017-18017
¸®´ª½º Ä¿³Î 4.11 ÀÌÀü ¹öÀü, 4.9.36 ÀÌÀüÀÇ 4.9.x ¹öÀüÀÇ net/netfilter/xt_TCPMSS.cÀÇ tcpmss_mangle_packet ÇÔ¼öÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ DoS °ø°ÝÀ» ÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>