English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28951
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý Windows È£½ºÆ®¿¡ ¼³Ä¡µÈ Thunderbird´Â 115.6 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼­ mfsa2023-55 ±Ç°íÀÇ ±Ç°í¿¡ ³ª¿­µÈ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- µðÁöÅÐ ¼­¸íµÈ ÅؽºÆ®°¡ Æ÷ÇÔµÈ PGP/MIME ÆäÀ̷ε带 ó¸®ÇÒ ¶§ ÅؽºÆ®ÀÇ Ã¹ ¹ø° ´Ü¶ôÀÌ »ç¿ëÀÚ¿¡°Ô Ç¥½ÃµÇÁö ¾Ê¾Ò½À´Ï´Ù. ÀÌ´Â ÅؽºÆ®°¡ MIME ¸Þ½ÃÁö·Î Çؼ®µÇ°í ù ¹ø° ´Ü¶ôÀÌ Ç×»ó ¸ÞÀÏ Çì´õ ¼½¼ÇÀ¸·Î 󸮵DZ⠶§¹®ÀÔ´Ï´Ù. ¼­¸íµÈ GIT Ä¿¹Ô°ú °°Àº ´Ù¸¥ ÄÁÅؽºÆ®ÀÇ µðÁöÅÐ ¼­¸íµÈ ÅؽºÆ®°¡ ¸ÞÀÏ ¸Þ½ÃÁö ½ºÇªÇο¡ »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-50762)
- µðÁöÅÐ ¼­¸íµÈ S/MIME ¸ÞÀÏ ¸Þ½ÃÁö¿¡ ¼­¸íÇÏ´Â °æ¿ì ¼±ÅÃÀûÀ¸·Î ¼­¸í ÀÛ¼º ³¯Â¥¿Í ½Ã°£À» ÁöÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. Á¸ÀçÇÏ´Â °æ¿ì Thunderbird´Â ¼­¸í ÀÛ¼º ³¯Â¥¿Í ¸Þ½ÃÁöÀÇ ³¯Â¥¿Í ½Ã°£À» ºñ±³ÇÏÁö ¾Ê¾ÒÀ¸¸ç ³¯Â¥ ¶Ç´Â ½Ã°£ ºÒÀÏÄ¡°¡ ÀÖ´õ¶óµµ À¯È¿ÇÑ ¼­¸íÀ» Ç¥½ÃÇß½À´Ï´Ù. À̸¦ ÅëÇØ ¹Þ´Â »ç¶÷¿¡°Ô ¸Þ½ÃÁö°¡ ´Ù¸¥ ³¯Â¥³ª ½Ã°£¿¡ Àü¼ÛµÈ °Íó·³ ÀλóÀ» ÁÙ ¼ö ÀÖ¾ú½À´Ï´Ù. (CVE-2023-50761)
- WebGL <code>DrawElementsInstanced</code> ¸Þ¼­µå´Â Mesa VM µå¶óÀ̹ö°¡ ÀÖ´Â ½Ã½ºÅÛ¿¡¼­ »ç¿ëµÇ´Â °æ¿ì Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ±â ½¬¿î »óÅ¿´½À´Ï´Ù. ÀÌ ¹®Á¦·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¿ø°ÝÀ¸·Î Äڵ带 ½ÇÇàÇϰųª »÷µå¹Ú½º¸¦ ÇÇÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-6856)
- ½Éº¼¸¯ ¸µÅ©¸¦ ÇØ°áÇÒ ¶§ Ãæµ¹ÀÌ ¹ß»ýÇÏ°í <code>readlink</code>¿¡ Àü´ÞµÇ´Â ¹öÆÛ°¡ ½ÇÁ¦·Î ÇÊ¿äÇÑ °Íº¸´Ù ÀÛÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹ö±×ÀÇ ¿µÇâÀº Unix ±â¹Ý ¿î¿µ üÁ¦(Android, Linux, MacOS)ÀÇ Thunderbird»ÓÀÔ´Ï´Ù. Windows´Â ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. (CVE-2023-6857)
- Thunderbird´Â OOM 󸮰¡ ºÒÃæºÐÇϱ⠶§¹®¿¡ <code>nsTextFragment</code>ÀÇ Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù. (CVE-2023-6858)
- ¸Þ¸ð¸®°¡ ¾Ð¹ÚµÇ¸é ¸Þ¸ð¸® ÇØÁ¦ ÈÄ »ç¿ë (Use After Free) »óÅ°¡ TLS ¼ÒÄÏ »ý¼º¿¡ ¿µÇâÀ»ÁÝ´Ï´Ù. (CVE-2023-6859)
- <code>VideoBridge</code>¸¦ »ç¿ëÇϸé ÄÜÅÙÃ÷ ÇÁ·Î¼¼½º°¡ ¿ø°Ý µðÄÚ´õ¿¡¼­ »ý¼ºÇÑ ÅؽºÃ³¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº »÷µå ¹Ú½º¸¦ À̽ºÄÉÀÌÇÁÇϱâ À§ÇØ ¾Ç¿ë µÉ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-6860)
- <code>nsWindow: : PickerOpen(void)</code> ¸Þ¼­µå´Â Çìµå¸®½º ¸ðµå¿¡¼­ ½ÇÇàÇÒ ¶§ Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ±â ½¬¿öÁ³½À´Ï´Ù. (CVE-2023-6861)
- <code>nsDNSService: : Init</code> ¸Þ¸ð¸® ÇØÁ¦ ÈÄ »ç¿ë(Use After Free)ÀÌ È®ÀεǾú½À´Ï´Ù. ÀÌ ¹®Á¦´Â ½ÃÀÛÇÏ´Â µ¿¾È µå¹°°Ô ¹ß»ýÇÕ´Ï´Ù. (CVE-2023-6862)
- <code>ShutdownObserver()</code> ´Â °¡»ó ¼Ò¸êÀÚ°¡ ¾ø´Â µ¿Àû À¯Çü¿¡ ÀÇÁ¸Çϱ⠶§¹®¿¡ Á¤ÀǵÇÁö ¾ÊÀº µ¿ÀÛÀ» À¯¹ßÇÒ ¼ö ÀÖ¾ú½À´Ï´Ù. (CVE-2023-6863)
- Firefox 120, Firefox ESR 115.5 ¹× Thunderbird 115.5¿¡ Á¸ÀçÇÏ´Â ¸Þ¸ð¸® ¾ÈÀü ¹ö±×. ÀÌ·¯ÇÑ ¹ö±× Áß ÀϺδ ¸Þ¸ð¸® ¼Õ»óÀÇ Áõ°Å¸¦ º¸¿© ÁÖ¸ç, ´ç»ç´Â ÃæºÐÇÑ ³ë·ÂÀ» ±â¿ï¿© ÀÌ·¯ÇÑ ºÎºÐÀ» ¾Ç¿ëÇÏ°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù°í ÃßÃøÇÏ°í ÀÖ½À´Ï´Ù.(CVE-2023-6864)

* Âü°í »çÀÌÆ®:
https://www.mozilla.org/en-US/security/advisories/mfsa2023-55/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Project, Thunderbird 115.6 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ Mozilla À¥ »çÀÌÆ®ÀÎ http://www.mozilla.com/thunderbird/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ThunderbirdÀÇ °¡Àå ÃֽŠ¹öÀü(115.6 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2023-50761,CVE-2023-50762,CVE-2023-6856,CVE-2023-6857,CVE-2023-6858,CVE-2023-6859,CVE-2023-6860,CVE-2023-6861,CVE-2023-6862 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)