English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25152
À§Çèµµ 40
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 10.5 Fix Pack 4 ÀÌÀüÀÇ IBM DB2 ¼­¹öÀÇ ¾î¶² ¹öÀüÀÌ ÇØ´ç È£½ºÆ®¿¡ °¡µ¿ ÁßÀÌ´Ù. IBM DB2ÀÇ 10.5 Fix Pack 4 ÀÌÀüÀÇ 10.5 ¹öÀüµéÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- JavaScript Object Notation(JSON-C)ó¸®, ¹®ÀÚ¿­ ÆĽÌ, Çؽà ÇÔ¼ö¿¡ °ü·ÃµÈ ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¼­ºñ½º °ÅºÎ°¡ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2013-6371)
- 'ALTER MODULE' ó¸® ½Ã ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¼­¹ö°¡ ÁßÁöµÇ°í ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2014-3094)
- 'UNION'À» »ç¿ëÇÏ´Â ¼­ºêÄõ¸®¸¦ °¡Áø 'SELECT'¸¦ ó¸® ½Ã ¿¡·¯°¡ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇØ ¼­ºñ½º °ÅºÎ°¡ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. (CVE-2014-3095)
- Columnar Data Engine (CDE) Å×À̺í°ú 'LOAD'󸮿¡ ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ ³»ºÎ Á¤º¸°¡ À¯ÃâµÉ ¼ö ÀÖ´Ù. (CVE-2014-4805)

* Âü°í »çÀÌÆ®:
http://www-01.ibm.com/support/docview.wss?uid=swg21647054#4
http://www-01.ibm.com/support/docview.wss?uid=swg24038261
http://www-01.ibm.com/support/docview.wss?uid=swg1IT02201
http://www-01.ibm.com/support/docview.wss?uid=swg21681631
http://www-01.ibm.com/support/docview.wss?uid=swg1IT02433
https://www-304.ibm.com/support/docview.wss?uid=swg21681723

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 10.5 Fix Pack 4 ÀÌÀüÀÇ 10.5 ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Database Fix Pack(10.5 Fix Pack 4 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-01.ibm.com/support/docview.wss?uid=swg24038261
°ü·Ã URL CVE-2013-6371,CVE-2014-3094,CVE-2014-3095,CVE-2014-4805 (CVE)
°ü·Ã URL 66715,69541,69546,69550 (SecurityFocus)
°ü·Ã URL (ISS)