°øÁö»çÇ×
º¸¾ÈÆÐÄ¡
°áÁ¦¹æ¹ý¾È³»
¼­ºñ½º ÀÌ¿ë¾à°ü
°³ÀÎÁ¤º¸Ãë±Þ¹æÄ§
ÀÚÁÖ¹¯´ÂÁú¹®
±â¼ú°¡À̵å
¹®ÀÇÇϱâ
Á¦ ¸ñ Adobe Flash Player ´ÙÁß Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í º¸¾È°øÁö - 2009-07-31
ÀÛ¼ºÀÚ Çϳª·ÎÈ£½ºÆÃ ( hosting@hhosting.co.kr ) µî·ÏÁ¤º¸ 2009-07-31 16:10:00 Á¶È¸¼ö 35457
Adobe Flash Player ´ÙÁß Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í º¸¾È°øÁö - 2009-07-31
¡à °³¿ä
o Adobe Flash Player/Adobe Air¿¡¼­ ±ÇÇÑ»ó½Â, ¹öÆÛ¿À¹öÇ÷Î, Ŭ¸¯ÀçÅ· µîÀÇ ´Ù¼ö Ãë¾àÁ¡ÀÌ ¹ß°ß
µÇ¾î º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¹ßÇ¥µÊ[1]
o ³·Àº ¹öÀüÀÇ Adobe Flash Player/Adobe Air »ç¿ëÀ¸·Î ¾Ç¼ºÄÚµå °¨¿° µîÀÇ »ç°í°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ½
À¸·Î »ç¿ëÀÚÀÇ ÁÖÀÇ ¹× ÃֽŹöÀü ¼³Ä¡°¡ ±Ç°íµÊ

¡à ¿µÇâ
o »ó±â Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚ´Â Á¶ÀÛµÈ SWF ÆÄÀÏÀÌ Æ÷ÇÔµÈ À¥ ÆäÀÌÁö¸¦ ¹æ¹®ÇÏ´Â ÇÇÇØÀÚÀÇ PC
¿¡¼­ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ ½ÇÇà½ÃŰ°Å³ª ¾Ç¼ºÄÚµå °¨¿° µî°ú °°Àº ¾Ç¼ºÇàÀ§¸¦ ÇÒ ¼ö ÀÖÀ½

¡à ¼³¸í
o Adobe Flash Player/Adobe Air Ãë¾àÁ¡ ÃÑ 10°ÇÀÌ ¾Æ·¡¿Í °°ÀÌ ¹ßÇ¥µÊ[1]
- ¿ø°ÝÄÚµå ½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡[2] (CVE-2009-1862)
- Ãë¾àÇÑ ATL Çì´õ¿¡ ÀÇÇØ ¹ß»ýÇÏ´Â Adobe Flash PlayerÀÇ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡[3,4,5]
(CVE-2009-0901, CVE-2009-2395, CVE-2009-2493)
¡Ø ATL(Active Template Library) : COM(Component Object Model) °´Ã¼ ÇÁ·Î±×·¡¹ÖÀ»
´Ü¼øÈ­ Çϱâ À§ÇÑ ÅÛÇø´ ±â¹Ý C++ Ŭ·¡½ºÀÇ ÁýÇÕÀ¸·Î À̸¦ ÀÌ¿ëÇÑ OLE ÀÚµ¿È­, ActiveX
ÄÁÆ®·Ñ µîÀÇ °³¹ßÀÌ °¡´ÉÇÔ(ÀÚ¼¼ÇÑ ³»¿ëÀº KISC º¸¾È°øÁö ÂüÁ¶[6])
- ¿ø°ÝÄÚµå½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ ±ÇÇÑ »ó½Â Ãë¾àÁ¡[7] (CVE-2009-1863)
- ¿ø°ÝÄÚµå½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ Èü¿À¹öÇ÷ΠÃë¾àÁ¡[8] (CVE-2009-1864)
- ¿ø°ÝÄÚµå½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ ³Î Æ÷ÀÎÅÍ Ãë¾àÁ¡[9] (CVE-2009-1865)
- ¿ø°ÝÄÚµå½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ ½ºÅÿÀ¹öÇ÷ΠÃë¾àÁ¡[10] (CVE-2009-1866)
- ¸µÅ©¿Í ´ÙÀ̾ó·Î±×¸¦ »ç¿ëÀÚ°¡ ¸ð¸£°Ô Ŭ¸¯Çϵµ·Ï À¯µµÇϴ Ŭ¸¯ÀçÅ· Ãë¾àÁ¡[11] (CVE-2009-
1867)
- URLÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼­ ¿ø°ÝÄÚµå½ÇÇàÀÌ °¡´ÉÇÑ Èü¿À¹öÇ÷ΠÃë¾àÁ¡[12] (CVE-2009-1868)
- ¿ø°ÝÄÚµå½ÇÇàÀ¸·Î ¿¬°è °¡´ÉÇÑ Á¤¼ö¿À¹öÇ÷ΠÃë¾àÁ¡[13] (CVE-2009-1869)
- Flash ÆÄÀÏ(È®ÀåÀÚ:SWF)ÀÌ Çϵåµð½ºÅ©¿¡ ÀúÀåµÉ ¶§ Á¤º¸°¡ ³ëÃâµÇ´Â Ãë¾àÁ¡[14] (CVE-2009-
1870)

¡à ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Adobe Flash Player 10.0.22.87 ÀÌÇÏ ¹öÀü
- Adobe Flash Player 9.0.159.0 ÀÌÇÏ ¹öÀü
- Adobe AIR 1.5.1 ÀÌÇÏ ¹öÀü

¡à ÇØ°á ¹æ¾È
o Adobe Flash Player 10.0.22.87 ÀÌÇÏ ¹öÀüÀÇ »ç¿ëÀÚ´Â 10.0.32.18 ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÒ °ÍÀ»
±Ç°íÇÔ
- Ç÷¹ÀÌ¾î ´Ù¿î·Îµå ¼¾ÅÍ[15]¿¡¼­ µ¿ÀÇ ¹× ¼³Ä¡ ¼±ÅÃ
(¡Ø ±¸±Û Åø¹Ù Ãß°¡ ¼³Ä¡°¡ ±âº»À¸·Î ¼³Á¤µÇ¾î ÀÖÀ¸´Ï ¼³Ä¡ Àü È®ÀÎ ÇÊ¿ä)
o Adobe Flash Player 10.0.32.18 ¹öÀüÀ¸·Î ¾÷±×·¹À̵尡 ¾î·Á¿î Adobe Flash Player 9.0.159.0
¹öÀü ÀÌÇÏ »ç¿ëÀÚ´Â Adobe Flash Player 9.0.246.0 ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÒ °ÍÀ» ±Ç°íÇÔ[16]
o Flash ÄÁÅÙÃ÷¸¦ »ç¿ëÇÏ´Â À¥¼­¹ö °ü¸®ÀÚ´Â ¾Æ·¡¿Í °°ÀÌ À¥ÆäÀÌÁö¸¦ ¼öÁ¤ÇÏ¿© ÀÌ¿ëÀÚµéÀÌ ÃÖ½Å
¹öÀü Flash Player¸¦ ¼³Ä¡Çϵµ·Ï ActiveX ¹öÀü ¼öÁ¤ ÇÊ¿ä
o ÇâÈÄ¿¡µµ À¯»ç Ãë¾àÁ¡ ³ëÃâ·Î ÀÎÇÑ ÇÇÇØ¿¹¹æÀ» À§ÇØ ¾Æ·¡¿Í °°ÀÌ ¾ÈÀüÇÑ ºê¶ó¿ì¡ ½À°üÀ» Áؼö
ÇØ¾ß ÇÔ
- ½Å·ÚµÇÁö ¾ÊÀº À¥»çÀÌÆ®ÀÇ Ç÷¡½Ã ÆÄÀÏ ´Ù¿î·Îµå ÁÖÀÇ
- ÀǽɵǴ À̸ÞÀÏ¿¡ Æ÷ÇÔµÈ Ç÷¡½Ã ÆÄÀÏ ¸µÅ©¸¦ ¹æ¹®ÇÏÁö ¾ÊÀ½

¡à ¿ë¾î ¼³¸í
o Adobe Flash Player: Adobe Flash³ª Adobe Flex µî¿¡¼­ »ý¼ºÇÑ SWF ÆÄÀÏÀ» ±¸µ¿ÇÏ´Â
ÇÁ·Î±×·¥
o SWF(Shockwave Flash): MacromediaÞä°¡ °³¹ßÇÑ ¸ÖƼ¹Ìµð¾î ¹× º¤ÅÍ ±×·¡ÇÈ ÆÄÀÏ Çü½Ä
À¸·Î ÁÖ·Î À¥¿¡¼­ »ç¿ëµÊ
o Adobe AIR(Adobe Integrated Runtime) : ÀÌ¹Ì ÀÔÁõµÈ À¥ ±â¼úÀ» ºê¶ó¿ìÀú ¿ÜºÎ µ¥½ºÅ©Åé¿¡¼­
½ÇÇàµÉ ¼ö ÀÖµµ·Ï µµ¿ÍÁÖ´Â ÇÁ·Î±×·¥ Á¦ÀÛ µµ±¸[17]
o Ŭ¸¯ÀçÅ· : »ç¿ëÀÚ°¡ À¥ ÆäÀÌÁö¸¦ Ŭ¸¯ ÇÒ ¶§ Àڽŵµ ¸ð¸£°Ô ÀǵµÇÏÁö ¾ÊÀº ±â´ÉÀ» ½ÇÇàÇÏ¿©
°ø°ÝÀÚ°¡ ÄÄÇ»ÅÍ¿¡ ´ëÇÑ Á¦¾î±Ç ȤÀº Áß¿ä Á¤º¸¸¦ ȹµæÇÏ´Â Ãë¾àÁ¡[18]

¡à ÂüÁ¶ »çÀÌÆ®
[1] http://www.adobe.com/support/security/bulletins/apsb09-10.html
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862
[3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0901
[4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2395
[5] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493
[6] http://www.krcert.or.kr/secureNoticeView.do?num=348&seq=-1
[7] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1863
[8] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1864
[9] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1865
[10] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1866
[11] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1867
[12] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1868
[13] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1869
[14] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1870
[15] http://www.adobe.com/go/getflash
[16] http://www.adobe.com/products/flashplayer/fp_distribution3.html
[17] http://www.adobe.com/products/air/
[18] http://en.wikipedia.org/wiki/Clickjacking

[Âü °í]
1. ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ : ±¹¹ø¾øÀÌ 118
ÃÑ 174 °Ç
¹øÈ£ Á¦¸ñ µî·ÏÀÏ Á¶È¸¼ö
102 [MS º¸¾È¾÷µ¥ÀÌÆ®]2010³â 1¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2010-01-13 2010-01-13 28750
101 PowerDNS Recursor Buffer Overflow Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ® ±Ç°í - 2010-01-13 2010-01-13 29384
100 Áö¿¥º¸µå(gmBoard) Ãë¾àÁ¡ ¹× ¼­ºñ½º ÁßÁö¿¡ µû¸¥ ÀÌ¿ëÀÚ ÁÖÀÇ - 2010-01-11 2010-01-11 29392
99 MS IIS ÆÄÀÏ È®ÀåÀÚ Ã³¸®¿À·ù Ãë¾àÁ¡ ÁÖÀÇ - 2009-12-29 2009-12-29 30204
98 Adobe Flash Player ¹× Air ´ÙÁß Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2009-12-10 2009-12-11 29763
97 [MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 12¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2009-12-09 2009-12-10 29361
96 MS IE Style Object Á¦·Îµ¥ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÇÇÇØ ÁÖÀÇ - 2009-11-24 2009-11-24 29964
95 [MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 11¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2009-11-11 2009-11-11 29347
94 [MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 10¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2009-10-14 2009-10-14 29062
93 Adobe Reader/Acrobat ½Å±Ô Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÇÇÇØ ÁÖÀÇ 2009-10-12 30326
92 [MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 9¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í 2009-09-09 30750
91 [MS09-039] MS WINS Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ 2009-08-12 33907
90 [MS09-040] MS Message Queuing ¼­ºñ½º Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â 2009-08-12 34070
89 [MS09-041] MS ¿öÅ©½ºÅ×ÀÌ¼Ç ¼­ºñ½º Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦ 2009-08-12 34216
88 [MS09-042] Telnet Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ 2009-08-12 34929
87 [MS09-043] MS Office Web Component Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ 2009-08-12 34506
86 [MS09-044] MS Remote Desktop Connection Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ 2009-08-12 34764
85 [MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 8¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í - 2009-08-12 2009-08-12 34174
  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10]  
1