English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28923
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý Windows È£½ºÆ®¿¡ ¼³Ä¡µÈ Thunderbird ¹öÀüÀº 78.9.1 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼­ mfsa2021-13 ±Ç°í¿¡ ¾ð±Þ µÈ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

-Thunderbird »ç¿ëÀÚ°¡ ÀÌÀü¿¡ AliceÀÇ OpenPGP Å°¸¦ °¡Á® ¿Ô°í Alice°¡ Å°ÀÇ À¯È¿ ±â°£À» ¿¬ÀåÇßÁö¸¸ AliceÀÇ ¾÷µ¥ÀÌÆ® µÈ Å°¸¦ ¾ÆÁ÷ °¡Á® ¿ÀÁö ¾ÊÀº °æ¿ì °ø°ÝÀÚ´Â À߸øµÈ ÇÏÀ§ Å°¿Í ÇÔ²² AliceÀÇ Å°ÀÇ Á¦ÀÛ µÈ ¹öÀüÀÌ Æ÷ÇÔ µÈ À̸ÞÀÏÀ» º¸³¾ ¼ö ÀÖ½À´Ï´Ù. , Thunderbird´Â ÀÌÈÄ¿¡ À¯È¿ÇÏÁö ¾ÊÀº ÇÏÀ§ Å°¸¦ »ç¿ëÇÏ·Á°í ½Ãµµ ÇÒ ¼ö ÀÖÀ¸¸ç ¾Ïȣȭ µÈ À̸ÞÀÏÀ» Alice¿¡°Ô º¸³»Áö ¸øÇÕ´Ï´Ù. (CVE-2021-23991)

-Thunderbird´Â OpenPGP Å°¿Í °ü·ÃµÈ »ç¿ëÀÚ ID¿¡ À¯È¿ÇÑ ÀÚü ¼­¸íÀÌ ÀÖ´ÂÁö È®ÀÎÇÏÁö ¾Ê¾Ò½À´Ï´Ù. °ø°ÝÀÚ´Â ¿ø·¡ »ç¿ëÀÚ ID¸¦ ¹Ù²Ù°Å³ª ´Ù¸¥ »ç¿ëÀÚ ID¸¦ Ãß°¡ÇÏ¿© OpenPGP Å°ÀÇ Á¦ÀÛ µÈ ¹öÀüÀ» ¸¸µé ¼ö ÀÖ½À´Ï´Ù. Thunderbird°¡ Á¦ÀÛ µÈ Å°¸¦ °¡Á®¿À°í ¼ö¶ôÇÏ´Â °æ¿ì, Thunderbird »ç¿ëÀÚ´Â °ÅÁþ »ç¿ëÀÚ ID°¡ »ó´ë¹æ¿¡°Ô ¼ÓÇÑ´Ù°í °ÅÁþÀ¸·Î °á·ÐÀ» ³»¸± ¼ö ÀÖ½À´Ï´Ù. (CVE-2021-23992)

-°ø°ÝÀÚ´Â »ç¿ëÀÚ°¡ ¾Ïȣȭ µÈ À̸ÞÀÏÀ» »ó´ë¹æ¿¡°Ô º¸³»´Â °ÍÀ» ¹æÁöÇϱâ À§ÇØ DoS °ø°ÝÀ» ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù. °ø°ÝÀÚ°¡ À߸øµÈ ÀÚü ¼­¸íÀÌÀÖ´Â ÇÏÀ§ Å°¸¦ »ç¿ëÇÏ¿© Á¦ÀÛ µÈ OpenPGP Å°¸¦ »ý¼ºÇÏ°í Thunderbird »ç¿ëÀÚ°¡ Á¦ÀÛ µÈ Å°¸¦ °¡Á® ¿À¸é Thunderbird°¡ À߸øµÈ ÇÏÀ§ Å°¸¦ »ç¿ëÇÏ·Á°í ÇÒ ¼ö ÀÖÁö¸¸ RNP ¶óÀ̺귯¸®´Â À̸¦ °ÅºÎÇÏ¿© ¾Ïȣȭ¸¦ À¯¹ßÇÕ´Ï´Ù. ºÒÇÕ°Ý. (CVE-2021-23993)

-OTR ÇÁ·ÎÅäÄÝ ±¸ÇöÀ» Á¦°øÇÏ´Â °øÀ¯ ¶óÀ̺귯¸®¸¦ ·Îµå ÇÒ ¶§ Thunderbird´Â óÀ½¿¡ Thunderbird¿¡¼­ ¹èÆ÷ÇÏÁö ¾ÊÀº ÆÄÀÏ À̸§À» »ç¿ëÇÏ¿© ¿­±â¸¦ ½ÃµµÇÕ´Ï´Ù. ÄÄÇ»ÅÍ°¡ ÀÌ¹Ì ´ëü ÆÄÀÏ À̸§ÀÇ ¾Ç¼º ¶óÀ̺귯¸®¿¡ °¨¿°µÇ¾ú°í ¾Ç¼º ¶óÀ̺귯¸®°¡ ½ÇÇà ¶óÀ̺귯¸® °Ë»ö °æ·Î¿¡ Æ÷ÇÔ µÈ µð·ºÅ丮¿¡ º¹»ç µÈ °æ¿ì Thunderbird´Â À߸øµÈ ¶óÀ̺귯¸®¸¦ ·ÎµåÇÕ´Ï´Ù. (CVE-2021-29949)

* Âü°í »çÀÌÆ®:
https://www.mozilla.org/en-US/security/advisories/mfsa2021-13/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Project, Thunderbird 78.9.1 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ Mozilla À¥ »çÀÌÆ®ÀÎ http://www.mozilla.com/thunderbird/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ThunderbirdÀÇ °¡Àå ÃֽŠ¹öÀü(78.9.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2021-23991,CVE-2021-23992,CVE-2021-23993,CVE-2021-29949 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)