CVE-2018-7286, CVE-2018-7287
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 2¿ù 21ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 21ÀÏ¿¡¼ 22ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2018-0206
Cisco Unified Communications ManagerÀÇ À¥ ±â¹Ý °ü¸® ÀÎÅÍÆäÀ̽ºÀÇ XSS Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ¾Ç¼º ÀԷ°ªÀ» ÀÎÅÍÆäÀ̽º¿¡ ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2018-7284
Asterisk 13.19.1 ¹öÀü, 14.x~14.7.5 ¹öÀü, 15.x~15.2.1 ¹öÀü, Certified Asterisk 13.18-cert2 ¹öÀüÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2018-7285
Asterisk 15.x~15.2.1 ¹öÀüÀÇ Null Æ÷ÀÎÅÍ Á¢±Ù ¹®Á¦·Î ½Ã½ºÅÛ ¸¶ºñ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2018-7286
Asterisk 13.19.1 ¹öÀü, 14.x~14.7.5 ¹öÀü, 15.x~15.2.1 ¹öÀü°ú Certified Asterisk 13.18-cert2 ¹öÀüÀÇ res_pjsipÀÇ Ãë¾àÁ¡À¸·Î ¿ø°Ý¿¡¼ ÀÎÁõµÈ »ç¿ëÀÚµéÀÌ ½Ã½ºÅÛÀ» ¸¶ºñ½Ãų ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2018-7287
Asterisk 15.x~15.2.1 ¹öÀüÀÇ res_http_websocket.cÀÇ Ãë¾àÁ¡À¸·Î Å©±â°¡ 0ÀÎ WebSocket ÆäÀ̷ε尡 Á¦´ë·Î 󸮵ÇÁö ¾Ê´Â´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>