English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28294
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°ÝÀÇ È£½ºÆ®¿¡´Â 6 Update 24 / 5.0 update 28 / 1.4.2_30 ÀÌÀüÀÇ Oracle Java SE ¶Ç´Â ±â¾÷¿ë Java°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
ÇØ´ç ¹öÀüÀÇ ´ÙÀ½°ú °°Àº ÄÄÆ÷³ÍÆ®´Â ÀáÀçÀûÀ¸·Î º¸¾È À̽´¿¡ ¿µÇâÀ» ¹Þ´Â´Ù.

- Deployment
- HotSpot
- Install
- JAXP
- Java Language
- JDBC
- Launcher
- Networking
- Security
- Sound
- Swing
- XML Digital Signature
- 2D

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Oracle µ¥ÀÌÅͺ£À̽º ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-11-082
http://www.zerodayinitiative.com/advisories/ZDI-11-083
http://www.zerodayinitiative.com/advisories/ZDI-11-084
http://www.zerodayinitiative.com/advisories/ZDI-11-085
http://www.zerodayinitiative.com/advisories/ZDI-11-086
http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
JDK/JRE 6 update 25, JDK update 5.0 update 29, SDK 1.4.2_30 or later
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ Oracle »ç´Â ÀÌ ¹®Á¦µéÀ» ÇØ°áÇÒ ¼ö ÀÖ´Â Critical Patch Update¸¦ ³» ³õ¾Ò´Ù. ÀûÀýÇÑ ÆÐÄ¡ ȹµæ ¹× Àû¿ë¿¡ °üÇÑ Á¤º¸´Â ´ÙÀ½ 2011³â 2¿ù Oracle Critical Patch Update¿¡¼­ ãÀ» ¼ö ÀÖ´Ù:
http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html
°ü·Ã URL CVE-2010-4422,CVE-2010-4447,CVE-2010-4448,CVE-2010-4450,CVE-2010-4451,CVE-2010-4452,CVE-2010-4454,CVE-2010-4462,CVE-2010-4463 (CVE)
°ü·Ã URL 46091,46386,46387,46388,46391,46393,46394,46395,46397,46398,46399,46400,46402,46403,46404,46405,46406,46407,46409,46410,46411 (SecurityFocus)
°ü·Ã URL (ISS)