English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14241
À§Çèµµ 40
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LSC
»ó¼¼¼³¸í ¿ø°Ý ½Ã½ºÅÛ¿¡´Â Thunderbird security updateÀÎ USN-4064-1ÀÌ ÆÐÄ¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÆÐÄ¡ Àü Thunderbird¿¡´Â ´ÙÀ½°ú °°Àº Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- Á¶ÀÛµÈ ¾ð¾îÆÑ ¼³Ä¡¸¦ ÅëÇÏ¿© »÷µå¹Ú½º¸¦ Å»ÃâÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-9811)

- ¸Þ¸ð¸®°¡ ¼Õ»óÀ¸·Î ÀÎÇØ ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11709)

- ³»ºÎ À©µµ¿ì Àç»ç¿ëÀ» ÅëÇÑ µµ¸ÞÀÎ ³»¿¡ ½ºÅ©¸³Æ® »ðÀÔ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11711)

- 308 ¸®´ÙÀÌ·ºÆ®¿¡ ÀÇÇØ NPAPI Ç÷¯±×Àΰú ÇÔ²² Cross-origin POST ¿äûÀÌ »ý¼ºµÇ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11712)

- HTTP/2 ij½Ã ½ºÆ®¸² ³»ÀÇ Use-after-free Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11713)

- Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃÀ» ¹ß»ýÇÏ´Â HTML ÆÄ½Ì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11715)

- Å»ÀÚ ±âÈ£(Caret character)·Î ÀÎÇØ µ¿ÀÏ Ãâó Á¤Ã¥À» ¹þ¾î³¯ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11717)

- NSS¿¡¼­ ƯÁ¤ curve25519 °³ÀÎ Å°¸¦ ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÏ¿© ¼­ºñ½º °ÅºÎ ¹× Á¤º¸À¯Ãâ Ãë¾àÁ¡ÀÌ ¹ß»ýÇÑ´Ù. (CVE-2019-11719)

- NSS¿¡¼­ ƯÁ¤ p256-ECDH °ø°³ Å°¸¦ ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÏ¿© ¼­ºñ½º °ÅºÎ°¡ ¹ß»ýÇÑ´Ù. (CVE-2019-11729)

- µð·ºÅ͸® ³»ÀÇ ¸ðµç ÆÄÀÏÀ» µ¿ÀÏ Ãâó Á¤Ã¥À¸·Î ó¸®ÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2019-11730)

* Âü°í »çÀÌÆ®:
https://usn.ubuntu.com/4064-1/

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö ¼­¹öÀÇ Thunderbird DPKG ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Ubuntu 16.04 LTS
Ubuntu 18.04 LTS
ÇØ°áÃ¥ Ä¿¸Çµå¶óÀο¡¼­ ´ÙÀ½°ú °°ÀÌ OS¸¦ ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
# apt-get upgrade
°ü·Ã URL CVE-2019-11709,CVE-2019-11711,CVE-2019-11712,CVE-2019-11713,CVE-2019-11715,CVE-2019-11717,CVE-2019-11719,CVE-2019-11729,CVE-2019-11730 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)