English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22922
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ¿ø°Ý ¼­¹öÀÇ PHPÀÇ ¹öÀüÀº 7.3.6 ÀÌÀü 7.3.x ÀÌ´Ù. ÇØ´ç ¹öÀüÀº ´ÙÀ½ÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
- sscanf ¸Þ¼Òµå°¡ 16 Áø¼ö °ªÀ» ÀÐÀ» ¼ö ¾ø±â ¶§¹®¿¡ gdImageCreateFromXbm¿¡ ÃʱâÈ­µÇÁö ¾ÊÀº Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ¹Î°¨ÇÑ Á¤º¸ÀÇ °ø°³¸¦ À§ÇØ °ø°ÝÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11038)
- integer overflow·Î ÀÎÇØ iconv.c : _php_iconv_mime_decode ()¿¡ ¹üÀ§ ¿Ü Àбâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ¹Î°¨ÇÑ Á¤º¸ÀÇ °ø°³¸¦ À§ÇØ °ø°ÝÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11039)
- Èü ±â¹Ý ¹öÆÛ ¿À¹ö Ç÷οì Á¶°ÇÀÌ php_jpg_get16¿¡ Á¸ÀçÇÕ´Ï´Ù. ħÀÔÀÚ´Â À̸¦ ¾Ç¿ëÇÏ¿© ¼­ºñ½º °ÅºÎ »óÅ ¶Ç´Â ÀÓÀÇ ÄÚµå ½ÇÇàÀ» À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11040)

* Âü°í »çÀÌÆ®:
http://php.net/ChangeLog-7.php#7.3.6

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PHP 7.3.6 ÀÌÀüÀÇ ¹öÀüµé
Any operating system Any version
ÇØ°áÃ¥ PHP À¥ »çÀÌÆ®ÀÎ http://www.php.net/downloads.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PHPÀÇ °¡Àå ÃֽŠ¹öÀü(7.3.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2019-11038,CVE-2019-11039,CVE-2019-11040 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)