English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14238
À§Çèµµ 40
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LSC
»ó¼¼¼³¸í ¿ø°Ý ½Ã½ºÅÛ¿¡´Â Firefox security updateÀÎ CESA-2019:1763ÀÌ ÆÐÄ¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÆÐÄ¡ Àü Firefox¿¡´Â ´ÙÀ½°ú °°Àº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2019-11709)

- Á¶ÀÛµÈ ¾ð¾îÆÑ ¼³Ä¡¸¦ ÅëÇÑ »÷µå¹Ú½º Å»Ãâ Ãë¾àÁ¡ (CVE-2019-9811)

- ³»ºÎ À©µµ¿ì Àç»ç¿ëÀ» ÅëÇÑ µµ¸ÞÀÎ ³»¿¡ ½ºÅ©¸³Æ® »ðÀÔ Ãë¾àÁ¡ (CVE-2019-11711)

- 308 ¸®´ÙÀÌ·ºÆ®¿¡ ÀÇÇØ NPAPI Ç÷¯±×Àΰú ÇÔ²² Cross-origin POST ¿äûÀÌ »ý¼ºµÇ´Â Ãë¾àÁ¡ (CVE-2019-11712)

- HTTP/2 ij½Ã ½ºÆ®¸² ³»ÀÇ Use-after-free Ãë¾àÁ¡ (CVE-2019-11713)

- Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃÀ» ¹ß»ýÇÏ´Â HTML ÆÄ½Ì Ãë¾àÁ¡ (CVE-2019-11715)

- Å»ÀÚ ±âÈ£(Caret character)·Î ÀÎÇØ µ¿ÀÏ Ãâó Á¤Ã¥À» ¹þ¾î³¯ ¼ö ÀÖ´Â Ãë¾àÁ¡ (CVE-2019-11717)

- µð·ºÅ͸® ³»ÀÇ ¸ðµç ÆÄÀÏÀ» µ¿ÀÏ Ãâó Á¤Ã¥À¸·Î ó¸®ÇÏ´Â Ãë¾àÁ¡ (CVE-2019-11730)

* Âü°í »çÀÌÆ®:
https://lists.centos.org/pipermail/centos-announce/2019-July/023365.html

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö ¼­¹öÀÇ Firefox RPM ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CentOS Linux Server (v. 7)
ÇØ°áÃ¥ ´ÙÀ½ ÀýÂ÷¿¡ µû¶ó ¿µÇâ¹Þ´Â ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
System -> Administration -> Software Update

¶Ç´Â Ä¿¸Çµå¶óÀο¡¼­ ´ÙÀ½°ú °°ÀÌ OS¸¦ ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
# yum update
°ü·Ã URL CVE-2019-11709,CVE-2019-11711,CVE-2019-11712,CVE-2019-11713,CVE-2019-11715,CVE-2019-11717,CVE-2019-11730,CVE-2019-9811 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)