English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28885
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 51.0 ÀÌÀüÀÇ Mozilla FirefoxÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Mozilla Firefox´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ °ø°³ ¼Ò½º ±â¹ÝÀÇ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Mozilla Firefox 51.0 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½ÀÇ Ãë¾àÁ¡À» Æ÷ÇÔÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.

- Mozilla °³¹ßÀÚ ¹× Ä¿¹Â´ÏƼ ¸â¹ö Christian Holler, Gary Kwong, Andre Bargull, Jan de Mooij, Tom Schuster, Oriol °¡ ¸Þ¸ð¸® ¾ÈÁ¤¼º ¹ö±×¸¦ ¹ß°ßÇÏ¿´´Ù. (CVE-2017-5373)

- Mozilla °³¹ßÀÚ ¹× Ä¿¹Â´ÏƼ ¸â¹ö Mozilla developers and community members Gary Kwong, Olli Pettay, Tooru Fujisawa, Carsten Book, Andrew McCreight, Chris Pearce, Ronald Crane, Jan de Mooij, Julian Seward, Nicolas Pierron, Randell Jesup, Esther
Monchari, Honza Bambas, Philipp°¡ ¸Þ¸ð¸® ¾ÈÁ¤¼º ¹ö±×¸¦ ¹ß°ßÇÏ¿´´Ù. (CVE-2017-5374)

- JIT code allocationÀÌ ASLR °ú DEP ¹æ¾î¸¦ ¿ìȸÇÒ ¼ö ÀÖ´Ù. (CVE-2017-5375)

- XSLT ¹®¼­¿¡¼­ XSLÀ» ´Ù·ê ¶§ ÇØÁ¦ ÈÄ »ç¿ë ¿¡·¯°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-5376)

- ±×¶óµð¾ðÆ®¸¦ »ç¿ëÇÑ Æû º¯È¯¿¡¼­ Skia¿¡ ¸Þ¸ð¸® ºØ±« Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-5377)

- ÀÚ¹Ù ½ºÅ©¸³Æ® ¿ÀºêÁ§Æ®¿¡¼­ ÆäÀÌÁö°£¿¡ ÇؽÃÄڵ带 ÅëÇÑ °øÀ¯°¡ ÀÌ·ç¾î Áø´Ù. ÇؽÃÄڵ带 ÅëÇØ °´Ã¼ÀÇ ÁÖ¼Ò°¡ ³ëÃâµÇ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-5378)

- À¥ ¾Ö´Ï¸ÞÀ̼ǿ¡ ÇØÁ¦ ÈÄ »ç¿ë Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-5379)

- DOM ¿¡¼­ SVG ÄÜÅÙÆ®¸¦ ´Ù·ê ¶§ ÇØÁ¦ ÈÄ »ç¿ë Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-5380)

- ÀÎÁõ¼­ ºä¾îÀÇ 'export' ÇÔ¼ö¸¦ ÅëÇØ ·ÎÄà ÆÄÀϽýºÅÛÀ» Ž»öÇÒ ¼ö ÀÖ´Ù. (CVE-2017-5381)

- ÇÇµå ¹Ì¸® º¸±â¸¦ ÅëÇÏ¿© ¿¡·¯³ª ¿¹¿Ü¸¦ º¼ ¼ö Àִµ¥ À̸¦ ÅëÇÏ¿© ³»ºÎ Á¤º¸°¡ À¯ÃâµÉ ¼ö ÀÖ´Ù. (CVE-2017-5382)

- URL¿¡ ÇÏÀÌÇ°ú µû¿ÈÇ¥¸¦ ´ëüÇÏ´Â À¯´ÏÄÚµå ¹®ÀÚ°¡ ÀÖÀ» ¶§ Á¦´ë·Î Ç¥½ÃÇÏÁö ¸øÇÏ¿© ÁÖ¼Ò ¹Ù¸¦ ÅëÇÑ DNS ½ºÇªÇÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. (CVE-2017-5383)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Project, Firefox 51.0 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ Mozilla Firefox ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.mozilla.or.kr/ko/ ¿¡¼­ FirefoxÀÇ °¡Àå ÃֽŠ¹öÀü(51.0 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2017-5373,CVE-2017-5374,CVE-2017-5375,CVE-2017-5376,CVE-2017-5377,CVE-2017-5378,CVE-2017-5379,CVE-2017-5380,CVE-2017-5381,CVE-2017-5382 (CVE)
°ü·Ã URL 95757,95758,95759,95761,95762,95763,95769 (SecurityFocus)
°ü·Ã URL (ISS)