English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25122
À§Çèµµ 40
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB2
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 9.1 Fix Pack 12 ÀÌÀüÀÇ IBM DB2 UDB ¼­¹öÀÇ ¾î¶² ¹öÀüÀÌ ÇØ´ç È£½ºÆ®¿¡ °¡µ¿ ÁßÀÌ´Ù. IBM DB2 Universal Database (UDB)ÀÇ 9.1 Fix Pack 12 ÀÌÀüÀÇ 9.1 ¹öÀüµéÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- 'db2asrrm' ÇÁ·Î¼¼½º¿¡¼­ Á¤¼öºÎÈ£ÀÇ ¿¡·¯·Î ÀÎÇÏ¿© heap-based ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº À©µµ¿ìÁî È£½ºÆ®¿¡´Â ¿µÇâÀÌ ¾ø´Ù. (#IC80561 / CVE-2012-0711)

- Stored procedure 'SQLJ.DB2_INSTALL_JAR'ÀÇ ¿¡·¯·Î ÀÎÇÏ¿© 'JAR' ÆÄÀÏÀÌ overwrite µÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº À©µµ¿ìÁî È£½ºÆ®¿¡´Â ¿µÇâÀÌ ¾ø´Ù. (#IC84019 / CVE-2012-2194)

- Stored procedures 'GET_WRAP_CFG_C' ¿Í 'GET_WRAP_CFG_C2' ÀÇ ¿¡·¯·Î ÀÎÇÏ¿© XML ÆÄÀÏ¿¡ ´ëÇÑ ºñ Àΰ¡µÈ Á¢±ÙÀ» ÇÒ ¼ö ÀÖ´Ù. (#IC84614 / CVE-2012-2196)

- Java stored procedure infrastructureÀÇ ¿¡·¯·Î ÀÎÇÏ¿© stack-based ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (#IC84555 / CVE-2012-2197)

* Âü°í »çÀÌÆ®:
http://www-01.ibm.com/support/docview.wss?uid=swg21588093
http://www-01.ibm.com/support/docview.wss?uid=swg1IC84019
http://www-01.ibm.com/support/docview.wss?uid=swg1IC84614
http://www-01.ibm.com/support/docview.wss?uid=swg1IC84555
http://www-01.ibm.com/support/docview.wss?uid=swg24033023

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 UDB 9.1 FixPack 12 ÀÌÀüÀÇ 9.1 ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Universal Database Fix Pack(9.1 Fix Pack 12 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-01.ibm.com/support/docview.wss?uid=swg24033023
°ü·Ã URL CVE-2012-0711,CVE-2012-2194,CVE-2012-2196,CVE-2012-2197 (CVE)
°ü·Ã URL 52326,54487 (SecurityFocus)
°ü·Ã URL (ISS)