CVE-2018-9307, CVE-2018-9309
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 4¿ù 4ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 4ÀÏ¿¡¼ 5ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2018-9304
Exiv2 0.26 ¹öÀüÀÇ bigtiffimage.cppÀÇ BigTiffImage::printIFDÀÇ µð¹ÙÀÌµå ¹ÙÀÌ Á¦·Î Ãë¾àÁ¡À¸·Î °ø°ÝÀÚµéÀÌ DoS °ø°ÝÀ» °¨ÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2018-9305
Exiv2 0.26 ¹öÀüÀÇ iptc.cÀÇ IptcData::printStructureÀÇ ¾Æ¿ô¿Àºê¹Ù¿îµå Ãë¾àÁ¡À¸·Î ½Ã½ºÅÛ ¸¶ºñ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù.
3. CVE-2018-9306
Exiv2 0.26 ¹öÀüÀÇ iptc.cÀÇ IptcData::printStructureÀÇ ¾Æ¿ô¿Àºê¹Ù¿îµå Ãë¾àÁ¡À¸·Î ½Ã½ºÅÛ ¸¶ºñ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù.
4. CVE-2018-9307
dsmall v20180320ÀÇ public/index.php/home/predeposit/index.htmlÀÇ pdr_sn ¸Å°³º¯¼öÀÇ XSS Ãë¾àÁ¡ÀÌ´Ù.
5. CVE-2018-9309
zzcms 8.2ÀÇ dl/dl_sendsms.phpÀÇ id ¸Å°³º¯¼öÀÇ SQL ÁÖÀÔ Ãë¾àÁ¡ÀÌ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>