English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50025
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡´Â ¿©·¯°¡Áö Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â ÇÁ·Î±×·¡¹Ö Ç÷§ÆûÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù.
Oracle(¿¹ÀüÀÇ Sun) Java SE³ª ºñÁö´Ï½º¿ë Java°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
ÇØ´ç ¹öÀüÀº 7 Update 7 ÀÌÀüÀÇ ¹öÀüÀÌ¸ç ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.

- ÇØ´ç ¹öÀü¿¡ Á¸ÀçÇÏ´Â sun.awt.SunToolKitŬ·¡½ºÀÇ 'getField'¿Í 'getMethod'¸Þ¼Òµå¿¡´Â ´Ù¸¥ Ŭ·¡½º¿¡ ´ëÇÑ Á¤º¸¸¦ Á¢±ÙÇÏ´Â °ÍÀ» ÀûÀýÈ÷ Á¦ÇÑÇÏÁö ¸øÇÑ´Ù. ¹øµé·Î Á¦°øµÇ´Â SunToolKitÀ» ÅëÇØ ´Ù¸¥ Ŭ·¡½ºµéÀÇ Çʵ峪 ¸Þ¼Òµå¿¡ ´ëÇÑ Á¤º¸¸¦ ȹµæÇϴµ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. (CVE-2012-0547)
- 'com.sun.beans.finder.ConstructorFinder'¸Þ¼Òµå¿Í 'com.sun.beans.finder.FieldFinder'¸Þ¼Òµå¿¡ ¸í½ÃµÇÁö ¾ÊÀº ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2012-1682, CVE-2012-3136)
- ¹øµé·Î Á¦°øµÇ´Â SunToolKitÀÇ 'setField'¸Þ¼Òµå¿¡ ¿Ã¹Ù¸£Áö ¾ÊÀº ±ÇÇÑÀ¸·Î ÀÛµ¿µÇ°Å³ª, °ø°ÝÀÚ°¡ Á¢±Ù¿¡ ´ëÇÑ ±ÇÇÑÀ» Á¦¾îÇÏ¿© ÄÚµå ½ÇÇà¿¡ ´ëÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2012-4681)

* ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
http://www.deependresearch.org/2012/08/java-7-0-day-vulnerability-information.html
http://thexploit.com/sec/java-facepalm/
http://www.oracle.com/technetwork/java/javase/7u7-relnotes-1835816.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Java SE 7 Update 6 and earlier
Microsoft Windows Any version
ÇØ°áÃ¥ JDK¿Í JREÀÇ °¡Àå ÃֽŠ¹öÀü(Java JDK / JRE 7 Update 7 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ°í ¿µÇâÀÌ ÀÖ´Â ¹öÀüÀº Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2012-0547,CVE-2012-1682,CVE-2012-3136,CVE-2012-4681 (CVE)
°ü·Ã URL 55213,55336,55337,55339 (SecurityFocus)
°ü·Ã URL (ISS)