English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50057
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 1.5.0_51 ÀÌÀüÀÇ Sun Java JDK / JREÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÇØ´ç Oracle Java JREÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÀÌ ¼ÒÇÁÆ®¿þ¾î¿¡´Â ´ÙÀ½ÀÇ ±¸¼º¿ä¼Ò¿¡ Á¤º¸À¯Ãâ Ãë¾àÁ¡, ±ÇÇÑ»ó½Â Ãë¾àÁ¡, ƯÁ¤ µ¥ÀÌÅÍ Á¶ÀÛ Ãë¾àÁ¡, º¸¾È ¿ìȸ Ãë¾àÁ¡, ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡, ÄÚµå½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- 2D
- AWT
- CORBA
- Deployment
- Hotspot
- Install
- JDBC
- JMX
- Libraries
- Networking
- Serialization
- Serviceability
- Sound

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
http://www.zerodayinitiative.com/advisories/ZDI-13-132/
http://www.zerodayinitiative.com/advisories/ZDI-13-151/
http://www.zerodayinitiative.com/advisories/ZDI-13-152/
http://www.zerodayinitiative.com/advisories/ZDI-13-153/
http://www.zerodayinitiative.com/advisories/ZDI-13-154/
http://www.zerodayinitiative.com/advisories/ZDI-13-155/
http://www.zerodayinitiative.com/advisories/ZDI-13-156/
http://www.zerodayinitiative.com/advisories/ZDI-13-157/
http://www.zerodayinitiative.com/advisories/ZDI-13-158/
http://www.zerodayinitiative.com/advisories/ZDI-13-159/
http://www.zerodayinitiative.com/advisories/ZDI-13-160/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Java JDK and JRE 5 Update 51 ÀÌÀü ¹öÀüµé
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ JDK¿Í JREÀÇ °¡Àå ÃֽŠ¹öÀü(Java JDK / JRE 5 Update 51 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ°í ¿µÇâÀÌ ÀÖ´Â ¹öÀüÀº Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
http://www.java.com/ko/
°ü·Ã URL CVE-2013-1500,CVE-2013-1571,CVE-2013-2400,CVE-2013-2407,CVE-2013-2412,CVE-2013-2437,CVE-2013-2442,CVE-2013-2443,CVE-2013-2444,CVE-2013-2445 (CVE)
°ü·Ã URL 60617,60618,60619,60620,60621,60622,60623,60624,60625,60626,60627,60629,60630,60631,60632,60633,60634,60635,60636,60637,60638,60639,60640 (SecurityFocus)
°ü·Ã URL (ISS)