Ãë¾àÁ¡ID |
50025 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡´Â ¿©·¯°¡Áö Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â ÇÁ·Î±×·¡¹Ö Ç÷§ÆûÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Oracle(¿¹ÀüÀÇ Sun) Java SE³ª ºñÁö´Ï½º¿ë Java°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÇØ´ç ¹öÀüÀº 7 Update 7 ÀÌÀüÀÇ ¹öÀüÀÌ¸ç ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
- ÇØ´ç ¹öÀü¿¡ Á¸ÀçÇÏ´Â sun.awt.SunToolKitŬ·¡½ºÀÇ 'getField'¿Í 'getMethod'¸Þ¼Òµå¿¡´Â ´Ù¸¥ Ŭ·¡½º¿¡ ´ëÇÑ Á¤º¸¸¦ Á¢±ÙÇÏ´Â °ÍÀ» ÀûÀýÈ÷ Á¦ÇÑÇÏÁö ¸øÇÑ´Ù. ¹øµé·Î Á¦°øµÇ´Â SunToolKitÀ» ÅëÇØ ´Ù¸¥ Ŭ·¡½ºµéÀÇ Çʵ峪 ¸Þ¼Òµå¿¡ ´ëÇÑ Á¤º¸¸¦ ȹµæÇϴµ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. (CVE-2012-0547) - 'com.sun.beans.finder.ConstructorFinder'¸Þ¼Òµå¿Í 'com.sun.beans.finder.FieldFinder'¸Þ¼Òµå¿¡ ¸í½ÃµÇÁö ¾ÊÀº ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2012-1682, CVE-2012-3136) - ¹øµé·Î Á¦°øµÇ´Â SunToolKitÀÇ 'setField'¸Þ¼Òµå¿¡ ¿Ã¹Ù¸£Áö ¾ÊÀº ±ÇÇÑÀ¸·Î ÀÛµ¿µÇ°Å³ª, °ø°ÝÀÚ°¡ Á¢±Ù¿¡ ´ëÇÑ ±ÇÇÑÀ» Á¦¾îÇÏ¿© ÄÚµå ½ÇÇà¿¡ ´ëÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2012-4681)
* ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html http://www.deependresearch.org/2012/08/java-7-0-day-vulnerability-information.html http://thexploit.com/sec/java-facepalm/ http://www.oracle.com/technetwork/java/javase/7u7-relnotes-1835816.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle Java SE 7 Update 6 and earlier Microsoft Windows Any version |
ÇØ°áÃ¥ |
JDK¿Í JREÀÇ °¡Àå ÃֽŠ¹öÀü(Java JDK / JRE 7 Update 7 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ°í ¿µÇâÀÌ ÀÖ´Â ¹öÀüÀº Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2012-0547,CVE-2012-1682,CVE-2012-3136,CVE-2012-4681 (CVE) |
°ü·Ã URL |
55213,55336,55337,55339 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|