English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25143
À§Çèµµ 40
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 9.7 Fix Pack 9 ÀÌÀüÀÇ IBM DB2 ¼­¹öÀÇ ¾î¶² ¹öÀüÀÌ ÇØ´ç È£½ºÆ®¿¡ °¡µ¿ ÁßÀÌ´Ù. IBM DB2ÀÇ 9.7 Fix Pack 9 ÀÌÀüÀÇ 9.7 ¹öÀüµéÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- DB2¿¡ Æ÷ÇÔµÈ GSKit¿¡ SSL, TLS¿¡ °ü·ÃµÈ ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¼­ºñ½º °ÅºÎ, Á¤º¸À¯Ãâ, ÀÓÀÇÀÇ root ÀÎÁõ±â°ü ÀÎÁõ¼­°¡ »ðÀԵǴ Ãë¾àÁ¡¿¡ ³ëÃâµÉ ¼ö ÀÖ´Ù. (CVE-2012-2190, CVE-2012-2191, CVE-2012-2203 / IC90395)
- db2aud¿Í db2flacc¿¡ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇÃ·Î¿ì ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ³»ºÎ °ø°ÝÀÚ°¡ ÀνºÅϽº ¼ÒÀ¯ÀÚÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù. (CVE-2013-3475 / IC92495)
- ±ÇÇÑÀÌ ¾ø´Â °ø°ÝÀÚ°¡ Å×ÀÌºí¿¡ SELECT, INSERT, UPDATE, DELETE ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-4033 / IC94523)
- XSLT Æļ­¿¡ ³Î Æ÷ÀÎÅÍ°¡ ÂüÁ¶µÇ´Â ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-5466 / IC97470)
- OLAP¸¦ Æ÷ÇÔÇÏ´Â Äõ¸®¸¦ ó¸®ÇÒ ¶§ ¿¡·¯°¡ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¿ø°Ý °ø°ÝÀÚ°¡ µ¥ÀÌÅͺ£À̽º¸¦ ´Ý°Å³ª ºñÈ°¼ºÈ­ ½Ãų ¼ö ÀÖ´Ù. (CVE-2013-6717 / IC95641)

* Âü°í »çÀÌÆ®:
https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_executing_a_query_with_an_olap_specification_causes_the_db2_server_to_terminate_database_connections_cve_2013_6717?lang=en_us
http://www-01.ibm.com/support/docview.wss?uid=swg21450666#9
http://www-01.ibm.com/support/docview.wss?uid=swg24036646

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 9.7 Fix Pack 9 ÀÌÀüÀÇ 9.7 ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Database Fix Pack(9.7 FixPack 9 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-01.ibm.com/support/docview.wss?uid=swg24036646
°ü·Ã URL CVE-2012-2190,CVE-2012-2191,CVE-2012-2203,CVE-2013-3475,CVE-2013-4033,CVE-2013-5466,CVE-2013-6717 (CVE)
°ü·Ã URL 54743,55185,60255,62018,64334,64336 (SecurityFocus)
°ü·Ã URL (ISS)