English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28782
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 3.0.195.21 ÀÌÀüÀÇ Google ChromeÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Google ChromeÀº Google¿¡¼­ °³¹ßÇÑ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Google Chrome 3.0.195.21 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- Google ChromeÀÇ RSS/ATOM Çؼ®±â´Â RSS/ATOM feed ¾È¿¡ Æ÷ÇÔµÈ ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®¸¦ ¿©°ú ¾øÀÌ ÀÐ¾î µéÀδÙ. °ø°ÝÀÚ°¡ °ü¸®ÇÏ´Â RSS/ATOM feed ¸µÅ©¿¡ Á¢±ÙÇϰųª, RSS/ATOM feed ¾È¿¡ ÀÓÀÇÀÇ ÀÚ¹Ù½ºÅ©¸³Æ®¸¦ Æ÷ÇÔÇϵµ·Ï Çã¿ëÇÏ´Â À¥»çÀÌÆ®¿¡ Á¢±ÙÇÏ°Ô µÇ¸é, »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú¿¡¼­ °ø°ÝÀÚ°¡ »ðÀÔÇÑ ÀÓÀÇÀÇ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ´Ù. (#21238)

- Google ChromeÀÇ getSVGDocument() ÇÔ¼ö´Â Á¢±Ù È®Àο¡ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ À¥ »çÀÌÆ®¿¡ ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ »ðÀÔµÈ SVG ¹®¼­¸¦ ¾÷·ÎµåÇÏ°í, SVG Æ÷¸Ë ¹®¼­¸¦ È£½ºÆÃÇÏ´Â °ø°Ý ´ë»ó À¥»çÀÌÆ®¿¡¼­ ÀÚ½ÅÀÇ SVG ¹®¼­¿¡ ´ëÇØ ÂüÁ¶Çϵµ·Ï ¿¬°á½ÃÅ°¸é, °ø°Ý ´ë»ó À¥»çÀÌÆ® ³»¿¡¼­ °ø°ÝÀÚÀÇ À¥»çÀÌÆ® Á¤Ã¥À¸·Î ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ´Ù. (#21338)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/
http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0252.html
http://code.google.com/p/chromium/issues/detail?id=21238
http://code.google.com/p/chromium/issues/detail?id=21338

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Google Chrome 3.0.195.21 ÀÌÀü ¹öÀü
Microsoft Windows Any version
ÇØ°áÃ¥ Google À¥ »çÀÌÆ®ÀÎ http://www.google.com/chrome/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Google ChromeÀÇ °¡Àå ÃֽŠ¹öÀü(3.0.195.21 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2009-3263,CVE-2009-3264 (CVE)
°ü·Ã URL 36416 (SecurityFocus)
°ü·Ã URL (ISS)