Ãë¾àÁ¡ID |
28951 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
¿ø°Ý Windows È£½ºÆ®¿¡ ¼³Ä¡µÈ Thunderbird´Â 115.6 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼ mfsa2023-55 ±Ç°íÀÇ ±Ç°í¿¡ ³ª¿µÈ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- µðÁöÅÐ ¼¸íµÈ ÅؽºÆ®°¡ Æ÷ÇÔµÈ PGP/MIME ÆäÀ̷ε带 ó¸®ÇÒ ¶§ ÅؽºÆ®ÀÇ Ã¹ ¹ø° ´Ü¶ôÀÌ »ç¿ëÀÚ¿¡°Ô Ç¥½ÃµÇÁö ¾Ê¾Ò½À´Ï´Ù. ÀÌ´Â ÅؽºÆ®°¡ MIME ¸Þ½ÃÁö·Î Çؼ®µÇ°í ù ¹ø° ´Ü¶ôÀÌ Ç×»ó ¸ÞÀÏ Çì´õ ¼½¼ÇÀ¸·Î 󸮵DZ⠶§¹®ÀÔ´Ï´Ù. ¼¸íµÈ GIT Ä¿¹Ô°ú °°Àº ´Ù¸¥ ÄÁÅؽºÆ®ÀÇ µðÁöÅÐ ¼¸íµÈ ÅؽºÆ®°¡ ¸ÞÀÏ ¸Þ½ÃÁö ½ºÇªÇο¡ »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-50762) - µðÁöÅÐ ¼¸íµÈ S/MIME ¸ÞÀÏ ¸Þ½ÃÁö¿¡ ¼¸íÇÏ´Â °æ¿ì ¼±ÅÃÀûÀ¸·Î ¼¸í ÀÛ¼º ³¯Â¥¿Í ½Ã°£À» ÁöÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. Á¸ÀçÇÏ´Â °æ¿ì Thunderbird´Â ¼¸í ÀÛ¼º ³¯Â¥¿Í ¸Þ½ÃÁöÀÇ ³¯Â¥¿Í ½Ã°£À» ºñ±³ÇÏÁö ¾Ê¾ÒÀ¸¸ç ³¯Â¥ ¶Ç´Â ½Ã°£ ºÒÀÏÄ¡°¡ ÀÖ´õ¶óµµ À¯È¿ÇÑ ¼¸íÀ» Ç¥½ÃÇß½À´Ï´Ù. À̸¦ ÅëÇØ ¹Þ´Â »ç¶÷¿¡°Ô ¸Þ½ÃÁö°¡ ´Ù¸¥ ³¯Â¥³ª ½Ã°£¿¡ Àü¼ÛµÈ °Íó·³ ÀλóÀ» ÁÙ ¼ö ÀÖ¾ú½À´Ï´Ù. (CVE-2023-50761) - WebGL <code>DrawElementsInstanced</code> ¸Þ¼µå´Â Mesa VM µå¶óÀ̹ö°¡ ÀÖ´Â ½Ã½ºÅÛ¿¡¼ »ç¿ëµÇ´Â °æ¿ì Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ±â ½¬¿î »óÅ¿´½À´Ï´Ù. ÀÌ ¹®Á¦·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¿ø°ÝÀ¸·Î Äڵ带 ½ÇÇàÇϰųª »÷µå¹Ú½º¸¦ ÇÇÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-6856) - ½Éº¼¸¯ ¸µÅ©¸¦ ÇØ°áÇÒ ¶§ Ãæµ¹ÀÌ ¹ß»ýÇÏ°í <code>readlink</code>¿¡ Àü´ÞµÇ´Â ¹öÆÛ°¡ ½ÇÁ¦·Î ÇÊ¿äÇÑ °Íº¸´Ù ÀÛÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹ö±×ÀÇ ¿µÇâÀº Unix ±â¹Ý ¿î¿µ üÁ¦(Android, Linux, MacOS)ÀÇ Thunderbird»ÓÀÔ´Ï´Ù. Windows´Â ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù. (CVE-2023-6857) - Thunderbird´Â OOM 󸮰¡ ºÒÃæºÐÇϱ⠶§¹®¿¡ <code>nsTextFragment</code>ÀÇ Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù. (CVE-2023-6858) - ¸Þ¸ð¸®°¡ ¾Ð¹ÚµÇ¸é ¸Þ¸ð¸® ÇØÁ¦ ÈÄ »ç¿ë (Use After Free) »óÅ°¡ TLS ¼ÒÄÏ »ý¼º¿¡ ¿µÇâÀ»ÁÝ´Ï´Ù. (CVE-2023-6859) - <code>VideoBridge</code>¸¦ »ç¿ëÇϸé ÄÜÅÙÃ÷ ÇÁ·Î¼¼½º°¡ ¿ø°Ý µðÄÚ´õ¿¡¼ »ý¼ºÇÑ ÅؽºÃ³¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº »÷µå ¹Ú½º¸¦ À̽ºÄÉÀÌÇÁÇϱâ À§ÇØ ¾Ç¿ë µÉ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-6860) - <code>nsWindow: : PickerOpen(void)</code> ¸Þ¼µå´Â Çìµå¸®½º ¸ðµå¿¡¼ ½ÇÇàÇÒ ¶§ Èü ¹öÆÛ ¿À¹öÇ÷ÎÀÇ ¿µÇâÀ» ¹Þ±â ½¬¿öÁ³½À´Ï´Ù. (CVE-2023-6861) - <code>nsDNSService: : Init</code> ¸Þ¸ð¸® ÇØÁ¦ ÈÄ »ç¿ë(Use After Free)ÀÌ È®ÀεǾú½À´Ï´Ù. ÀÌ ¹®Á¦´Â ½ÃÀÛÇÏ´Â µ¿¾È µå¹°°Ô ¹ß»ýÇÕ´Ï´Ù. (CVE-2023-6862) - <code>ShutdownObserver()</code> ´Â °¡»ó ¼Ò¸êÀÚ°¡ ¾ø´Â µ¿Àû À¯Çü¿¡ ÀÇÁ¸Çϱ⠶§¹®¿¡ Á¤ÀǵÇÁö ¾ÊÀº µ¿ÀÛÀ» À¯¹ßÇÒ ¼ö ÀÖ¾ú½À´Ï´Ù. (CVE-2023-6863) - Firefox 120, Firefox ESR 115.5 ¹× Thunderbird 115.5¿¡ Á¸ÀçÇÏ´Â ¸Þ¸ð¸® ¾ÈÀü ¹ö±×. ÀÌ·¯ÇÑ ¹ö±× Áß ÀϺδ ¸Þ¸ð¸® ¼Õ»óÀÇ Áõ°Å¸¦ º¸¿© ÁÖ¸ç, ´ç»ç´Â ÃæºÐÇÑ ³ë·ÂÀ» ±â¿ï¿© ÀÌ·¯ÇÑ ºÎºÐÀ» ¾Ç¿ëÇÏ°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù°í ÃßÃøÇÏ°í ÀÖ½À´Ï´Ù.(CVE-2023-6864)
* Âü°í »çÀÌÆ®: https://www.mozilla.org/en-US/security/advisories/mfsa2023-55/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Mozilla Project, Thunderbird 115.6 ÀÌÀüÀÇ ¹öÀüµé Microsoft Windows Any version Linux Any version |
ÇØ°áÃ¥ |
Mozilla À¥ »çÀÌÆ®ÀÎ http://www.mozilla.com/thunderbird/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ThunderbirdÀÇ °¡Àå ÃֽŠ¹öÀü(115.6 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2023-50761,CVE-2023-50762,CVE-2023-6856,CVE-2023-6857,CVE-2023-6858,CVE-2023-6859,CVE-2023-6860,CVE-2023-6861,CVE-2023-6862 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|