English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28875
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 23.0 ÀÌÀüÀÇ Mozilla FirefoxÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Mozilla Firefox´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ °ø°³ ¼Ò½º ±â¹ÝÀÇ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Mozilla Firefox 23.0 ÀÌÀüÀÇ 22.x ¹öÀüµéÀº ´ÙÀ½ÀÇ Ãë¾àÁ¡À» Æ÷ÇÔÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.

- memory corruptionÀÌ ¹ß»ýÇÏ´Â ´Ù¾çÇÑ ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-1701, CVE-2013-1702)

- DOM ¼öÁ¤¿¡¼­ 'SetBody'¸¦ »ç¿ëÇÒ¶§¿Í 'Certificate Request Message'¸¦ »ý¼ºÇÒ¶§ Use-after-free ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2013-1704, CVE-2013-1705)

- ±ä path °ªÀ» ´Ù·ê ¶§ update service¿Í 'maintenanceservice.exe'¿¡¼­ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2013-1706, CVE-2013-1707)

- Ưº°È÷ Á¶ÀÛµÈ WAV ¿Àµð¿À ÆÄÀÏÀ» ´Ù·ê ¶§ 'nsCString::CharAt' ÇÔ¼ö¿¡ ¿¡·¯°¡ Á¸ÀçÇØ ¾îÇø®ÄÉÀ̼ÇÀÌ Å©·¡½¬µÉ ¼ö ÀÖ´Ù. (CVE-2013-1708)

- HTML frame°ú history handling, 'XrayWrappers', JavaScript URI handling, 'XMLHttpRequest'¸¦ »ç¿ëÇÏ´Â web workers¿¡ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇØ ross-site scripting °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2013-1709, CVE-2013-1711, CVE-2013-1713,
CVE-2013-1714)

- 'Certificate Request Message Format' (CRMF) »ý¼º ¿äû¿¡ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯°¡ Á¸ÀçÇØ cross-site scripting °ø°ÝÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2013-1710)

- update service, full installer, stub installer¿¡ DLL path loading ¿¡·¯°¡ Á¸ÀçÇØ ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù. (CVE-2013-1712, CVE-2013-1715)

- Java applets °ú 'file:///' URI¿¡ ¿¡·¯°¡ Á¸ÀçÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2013-1717)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Project, Firefox 23.0 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ Mozilla Firefox ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.mozilla.or.kr/ko/ ¿¡¼­ FirefoxÀÇ °¡Àå ÃֽŠ¹öÀü(23.0 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2013-1701,CVE-2013-1702,CVE-2013-1704,CVE-2013-1705,CVE-2013-1706,CVE-2013-1707,CVE-2013-1708,CVE-2013-1709,CVE-2013-1710,CVE-2013-1711 (CVE)
°ü·Ã URL 61864,61867,61869,61871,61872,61873,61874,61875,61876,61877,61878,61882,61883,61896,61900 (SecurityFocus)
°ü·Ã URL (ISS)