CVE-2018-12073, CVE-2018-12104
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 6¿ù 17ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 17ÀÏ¿¡¼ 18ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2018-12029
Phusion Passenger 3.x~5.x±îÁö ¹öÀüÀÇ nginx ¸ðµâÀÇ ·¹À̽º ÄÁµð¼Ç Ãë¾àÁ¡À¸·Î ·ÎÄÃÀÇ °ø°ÝÀÚ°¡ ±ÇÇÑÀ» »ó½Â½Ãų ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2018-12071
CodeIgniter 3.1.9 ÀÌÀü ¹öÀüÀÇ Session FixationÀÇ Session LibraryÀÇ session.use_strict_modeÀÇ Ãë¾àÁ¡ÀÌ´Ù.
3. CVE-2018-12072
Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 Æß¿þ¾îÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Åڳݿ¡ Á¢±ÙÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
4. CVE-2018-12073
Eminent EM4544 9.10 ±â±âÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ °ü¸®ÀÚ ºñ¹Ð¹øÈ£¸¦ º¯°æ½Ãų ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2018-12104
Airbnb Knowledge Repo 0.7.4 ¹öÀüÀÇ XSS Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¸¦ ÁÖÀÔ½Ãų ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>