Ãë¾àÁ¡ID |
28782 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â 3.0.195.21 ÀÌÀüÀÇ Google ChromeÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Google ChromeÀº Google¿¡¼ °³¹ßÇÑ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Google Chrome 3.0.195.21 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- Google ChromeÀÇ RSS/ATOM Çؼ®±â´Â RSS/ATOM feed ¾È¿¡ Æ÷ÇÔµÈ ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®¸¦ ¿©°ú ¾øÀÌ ÀÐ¾î µéÀδÙ. °ø°ÝÀÚ°¡ °ü¸®ÇÏ´Â RSS/ATOM feed ¸µÅ©¿¡ Á¢±ÙÇϰųª, RSS/ATOM feed ¾È¿¡ ÀÓÀÇÀÇ ÀÚ¹Ù½ºÅ©¸³Æ®¸¦ Æ÷ÇÔÇϵµ·Ï Çã¿ëÇÏ´Â À¥»çÀÌÆ®¿¡ Á¢±ÙÇÏ°Ô µÇ¸é, »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú¿¡¼ °ø°ÝÀÚ°¡ »ðÀÔÇÑ ÀÓÀÇÀÇ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ´Ù. (#21238)
- Google ChromeÀÇ getSVGDocument() ÇÔ¼ö´Â Á¢±Ù È®Àο¡ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ À¥ »çÀÌÆ®¿¡ ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ »ðÀÔµÈ SVG ¹®¼¸¦ ¾÷·ÎµåÇÏ°í, SVG Æ÷¸Ë ¹®¼¸¦ È£½ºÆÃÇÏ´Â °ø°Ý ´ë»ó À¥»çÀÌÆ®¿¡¼ ÀÚ½ÅÀÇ SVG ¹®¼¿¡ ´ëÇØ ÂüÁ¶Çϵµ·Ï ¿¬°á½ÃÅ°¸é, °ø°Ý ´ë»ó À¥»çÀÌÆ® ³»¿¡¼ °ø°ÝÀÚÀÇ À¥»çÀÌÆ® Á¤Ã¥À¸·Î ¾ÇÀÇÀûÀÎ ÀÚ¹Ù½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ´Ù. (#21338)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/ http://archives.neohapsis.com/archives/fulldisclosure/2009-09/0252.html http://code.google.com/p/chromium/issues/detail?id=21238 http://code.google.com/p/chromium/issues/detail?id=21338
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Google Chrome 3.0.195.21 ÀÌÀü ¹öÀü Microsoft Windows Any version |
ÇØ°áÃ¥ |
Google À¥ »çÀÌÆ®ÀÎ http://www.google.com/chrome/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Google ChromeÀÇ °¡Àå ÃֽŠ¹öÀü(3.0.195.21 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2009-3263,CVE-2009-3264 (CVE) |
°ü·Ã URL |
36416 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|