CVE-2018-6393, CVE-2018-6382
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 1¿ù 29ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 29ÀÏ¿¡¼ 30ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2016-10711
Apsis Pound 2.8a ÀÌÀü ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î Á¶ÀÛµÈ Çì´õµéÀ» ÅëÇØ ¿äûÀ» Áß°£¿¡ ¹æÇØÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù. CVE-2005-3751°ú ´Ù¸¥ Ãë¾àÁ¡ÀÌ´Ù.
2. CVE-2018-0101
Cisco Adaptive Security Appliance (ASA) SoftwareÀÇ SSL VPN ±â´É¼º¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î ÀÎÁõ¹ÞÁö ¸øÇÑ ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛÀ» ħÇØÇϰųª ¿ø°Ý ÄÚµå ½ÇÇàÀ» ÇÒ ¼ö ÀÖ°Ô µÈ´Ù. Cisco Bug ID´Â CSCvg35618ÀÌ´Ù.
3. CVE-2018-3835
Per Face Texture ¸ÅÇÎ ¾ÖÇø®ÄÉÀÌ¼Ç 2.2 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°ÝÀ» ½Ç½ÃÇØ ÄÚµå ½ÇÇàÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2018-6393
FreePBX 10.13.66-32ºñÆ®ÀÇ post-authentication SQL ÁÖÀÔ Ãë¾àÁ¡ÀÌ´Ù.
5. CVE-2018-6382
MantisBT 2.10.0 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ »ç¿ëÀÚµéÀÌ SQL ÀÎÁ§¼Ç °ø°ÝÀ» ½Ç½ÃÇÒ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>