·Î±×ÀÎ | ȸ¿ø°¡ÀÔ | ±â»çÁ¦º¸ | ½ºÅ©·¦ | ´º½º·¹ÅÍ ½Åû
Home > Àüü±â»ç

¾îµµºñ, ÀÓÀÇÄÚµå ½ÇÇà Ãë¾àÁ¡ µî ÇØ°áÇÑ ÆÐÄ¡ ¹ßÇ¥

ÀÔ·Â : 2015-10-15 11:08
ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â īī¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â
¾îµµºñ Ç÷¡½Ã Ç÷¹À̾î(Adobe Flash Player) ½Å±Ô Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í

[º¸¾È´º½º ¹Î¼¼¾Æ] ¾îµµºñ(Adobe)»ç´Â Ç÷¡½Ã Ç÷¹À̾î(Flash Player)¿¡¼­ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥Çß´Ù. ³·Àº ¹öÀü »ç¿ëÀÚ´Â ¾Ç¼ºÄÚµå °¨¿°¿¡ Ãë¾àÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÇØ°á¹æ¾È¿¡ µû¶ó ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ´Â °ÍÀÌ ¾ÈÀüÇÏ´Ù.

¡ã¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î


¹ßÇ¥µÈ Adobe Flash Player Ãë¾àÁ¡Àº ¡âÁ¤º¸³ëÃâ°ú same-origin Á¤Ã¥À» ¿ìȸÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE -2015-7628) ¡âFlash broker API¿¡ ½ÉÃþ ¹æ¾î ±â´É Æ÷ÇÔ(CVE-2015-5569) ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â use-after-free Ãë¾àÁ¡(CVE-2015-7629, CVE-2015-7631, CVE-2015-7643, CVE-2015-7644) ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ (CVE-2015-7632) ¡âÀÓÀÇÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡(CVE-2015-7625, CVE-2015-7626, CVE-2015-7627, CVE-2015-7630, CVE-2015-7633, CVE-2015-7634) µîÀÌ´Ù.

À©µµ¿ìÁî, ¸Æ ȯ°æÀÇ Adobe Flash Player desktop runtime »ç¿ëÀÚ´Â Adobe Flash Player Download Center¿¡ ¹æ¹®ÇÏ¿© ÃֽйöÀüÀ» ¼³Ä¡Çϰųª, ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ÀÌ¿ëÇØ 19.0.0.207¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇØ Ãë¾àÁ¡À» ÇØ°áÇÒ ¼ö ÀÖ´Ù.

Adobe Flash Player Extended Support Release »ç¿ëÀÚ´Â 18.0.0.252 ¹öÀüÀ¸·Î , ¸®´ª½º ȯ°æÀÇ Adobe Flash Player »ç¿ëÀÚ´Â 11.2.202.535 ¹öÀüÀ¸·Î, AIR desktop runtime, AIR SDK °ú Compiler, AIR for Android»ç¿ëÀÚ´Â 19.0.0.213 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¸é µÈ´Ù.

Adobe Flash Player°¡ ¼³Ä¡µÈ Google ChromeÀº ÀÚµ¿À¸·Î Ãֽо÷µ¥ÀÌÆ® ¹öÀüÀÌ Àû¿ëµÇ¸ç, ±¸±Û Å©·Ò ¹× À©µµ¿ì 8.x, 10 ¹öÀüÀÇ ÀÎÅÍ³Ý ÀͽºÇ÷η¯ 10, 11, EDGE¿¡ Adobe Flash Player¸¦ ¼³Ä¡ÇÑ »ç¿ëÀÚ´Â ÀÚµ¿À¸·Î Ãֽо÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ´Ù.

ÀÌ¿Í °ü·ÃÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ Âü°í»çÀÌÆ®¸¦ È®ÀÎÇϰųª Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)·Î ¹®ÀÇÇÏ¸é µÈ´Ù.

[Âü°í»çÀÌÆ®]
1. https://helpx.adobe.com/security/products/flash-player/apsb15-25.html

[¿ë¾î Á¤¸®]
-Use-After-Free Ãë¾àÁ¡
: ¼ÒÇÁÆ®¿þ¾î ±¸Çö ½Ã µ¿Àû ȤÀº Á¤ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸®¸¦ ÇØÁ¦ÇßÀ½¿¡µµ ºÒ±¸Çϰí À̸¦ °è¼Ó ÂüÁ¶(»ç¿ë)ÇÏ¿© ¹ß»ýÇÏ´Â Ãë¾àÁ¡
-Adobe AIR(Adobe Integrated Runtime): HTML, JavaScript, Adobe Flash ¹× ActionScript¸¦ »ç¿ëÇÏ¿© ºê¶ó¿ìÀúÀÇ Á¦¾à ¾øÀÌ µ¶¸³ ½ÇÇàÇü ¸ð¹ÙÀÏ ¹× µ¥½ºÅ©Å¾ À¥ ¾ÖÇø®ÄÉÀ̼ÇÀ» ±¸ÃàÇϰųª »ç¿ëÇÒ ¼ö Àִ ȯ°æÀ» Á¦°øÇÏ´Â µµ±¸
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]

<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>

  •  
  • 1
  • ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â īī¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â

  • ¡°
  •  SNS¿¡¼­µµ º¸¾È´º½º¸¦ ¹Þ¾Æº¸¼¼¿ä!! 
  • ¡±
2025 º¸¾È½ÃÀå ¹é¼­ À§Áîµð¿£¿¡½º 2018
¼³¹®Á¶»ç
SKÅÚ·¹ÄÞ ÇØÅ· »çÅ·ΠÃÖ±Ù ÀÕ½´°¡ µÇ°í ÀÖ´Â ¡®BPFµµ¾î¡¯ °ü·Ã, ¾î¶² ¼Ö·ç¼ÇÀ» »ç¿ëÁßÀΰ¡¿ä?
¾È·¦ V3 Net for Linux
¼Ò¸¸»ç Server-i
ÆÄÀÌ¿À¸µÅ© Á¡°Ë µµ±¸
À×Ä«ÀÎÅÍ³Ý Àü¿ë ¹é½Å
Æ®·»µå ¸¶ÀÌÅ©·Î ¹é½Å
±âŸ ±¹»ê(¼Ö·ç¼Ç¸íÀº ´ñ±Û·Î)
±âŸ ¿Ü»ê(¼Ö·ç¼Ç¸íÀº ´ñ±Û·Î)
»ç¿ëÇÏÁö ¾Ê´Â´Ù