Ãë¾àÁ¡ID |
28875 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â 23.0 ÀÌÀüÀÇ Mozilla FirefoxÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Mozilla Firefox´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ °ø°³ ¼Ò½º ±â¹ÝÀÇ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Mozilla Firefox 23.0 ÀÌÀüÀÇ 22.x ¹öÀüµéÀº ´ÙÀ½ÀÇ Ãë¾àÁ¡À» Æ÷ÇÔÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
- memory corruptionÀÌ ¹ß»ýÇÏ´Â ´Ù¾çÇÑ ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-1701, CVE-2013-1702)
- DOM ¼öÁ¤¿¡¼ 'SetBody'¸¦ »ç¿ëÇÒ¶§¿Í 'Certificate Request Message'¸¦ »ý¼ºÇÒ¶§ Use-after-free ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-1704, CVE-2013-1705)
- ±ä path °ªÀ» ´Ù·ê ¶§ update service¿Í 'maintenanceservice.exe'¿¡¼ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2013-1706, CVE-2013-1707)
- Ưº°È÷ Á¶ÀÛµÈ WAV ¿Àµð¿À ÆÄÀÏÀ» ´Ù·ê ¶§ 'nsCString::CharAt' ÇÔ¼ö¿¡ ¿¡·¯°¡ Á¸ÀçÇØ ¾îÇø®ÄÉÀ̼ÇÀÌ Å©·¡½¬µÉ ¼ö ÀÖ´Ù. (CVE-2013-1708)
- HTML frame°ú history handling, 'XrayWrappers', JavaScript URI handling, 'XMLHttpRequest'¸¦ »ç¿ëÇÏ´Â web workers¿¡ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇØ ross-site scripting °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2013-1709, CVE-2013-1711, CVE-2013-1713, CVE-2013-1714)
- 'Certificate Request Message Format' (CRMF) »ý¼º ¿äû¿¡ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇØ cross-site scripting °ø°ÝÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2013-1710)
- update service, full installer, stub installer¿¡ DLL path loading ¿¡·¯°¡ Á¸ÀçÇØ ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2013-1712, CVE-2013-1715)
- Java applets °ú 'file:///' URI¿¡ ¿¡·¯°¡ Á¸ÀçÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2013-1717)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Mozilla Project, Firefox 23.0 ÀÌÀüÀÇ ¹öÀüµé Microsoft Windows Any version Linux Any version |
ÇØ°áÃ¥ |
Mozilla Firefox ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.mozilla.or.kr/ko/ ¿¡¼ FirefoxÀÇ °¡Àå ÃֽŠ¹öÀü(23.0 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2013-1701,CVE-2013-1702,CVE-2013-1704,CVE-2013-1705,CVE-2013-1706,CVE-2013-1707,CVE-2013-1708,CVE-2013-1709,CVE-2013-1710,CVE-2013-1711 (CVE) |
°ü·Ã URL |
61864,61867,61869,61871,61872,61873,61874,61875,61876,61877,61878,61882,61883,61896,61900 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|