Ãë¾àÁ¡ID |
22923 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
¿ø°Ý ¼¹öÀÇ PHPÀÇ ¹öÀüÀº 7.2.19 ÀÌÀü 7.2.x ÀÌ´Ù. ÇØ´ç ¹öÀüÀº ´ÙÀ½ÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. - sscanf ¸Þ¼Òµå°¡ 16 Áø¼ö °ªÀ» ÀÐÀ» ¼ö ¾ø±â ¶§¹®¿¡ gdImageCreateFromXbm¿¡ ÃʱâȵÇÁö ¾ÊÀº Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ¹Î°¨ÇÑ Á¤º¸ÀÇ °ø°³¸¦ À§ÇØ °ø°ÝÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11038) - integer overflow·Î ÀÎÇØ iconv.c : _php_iconv_mime_decode ()¿¡ ¹üÀ§ ¿Ü Àбâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ¹Î°¨ÇÑ Á¤º¸ÀÇ °ø°³¸¦ À§ÇØ °ø°ÝÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11039) - Èü ±â¹Ý ¹öÆÛ ¿À¹ö Ç÷οì Á¶°ÇÀÌ php_jpg_get16¿¡ Á¸ÀçÇÕ´Ï´Ù. ħÀÔÀÚ´Â À̸¦ ¾Ç¿ëÇÏ¿© ¼ºñ½º °ÅºÎ »óÅ ¶Ç´Â ÀÓÀÇ ÄÚµå ½ÇÇàÀ» À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-11040)
* Âü°í »çÀÌÆ®: http://php.net/ChangeLog-7.php#7.2.19
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHP 7.2.19 ÀÌÀüÀÇ ¹öÀüµé Any operating system Any version |
ÇØ°áÃ¥ |
PHP À¥ »çÀÌÆ®ÀÎ http://www.php.net/downloads.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHPÀÇ °¡Àå ÃֽŠ¹öÀü(7.2.19 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2019-11038,CVE-2019-11039,CVE-2019-11040 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|