English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50117
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý À©µµ¿ìÁî È£½ºÆ®¿¡ Wireshark 2.0.11 ÀÌÀü 2.0.x ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç, ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- wiretap/netscaler.c ÆÄÀÏÀÇ nstrace_read_v20(), nstrace_read_v30() ÇÔ¼öÀÇ Netscaler ÆÄÀÏ Æļ­¿¡¼­ ÀԷ°©À» ´Ù·ê ¶§ ¹«ÇÑ ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6467)

- wiretap/netscaler.c ÆÄÀÏÀÇ ¿©·¯ ÇÔ¼ö¿¡¼­ ·¹ÄÚµå ±æÀ̸¦ ´Ù·ê ¶§ °æ°è °ª ÃÊ°ú Àб⠿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6468)

- epan/dissectors/packet-ldss.c ÆÄÀÏÀÇ dissect_ldss_transfer() ÇÔ¼ö¿¡¼­ ¸Þ¸ð¸® ÇÒ´ç ¿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6469)

- ŸÀÓ ½ºÅÆÇÁ¸¦ ´Ù·ê ¶§ epan/dissectors/packet-iax2.c ÆÄÀÏÀÇ iax2_add_ts_fields() ÇÔ¼ö¿¡¼­ ¹«ÇÑ ·çÇÁ »óÅ°¡ ¹ß»ýÇÑ´Ù. (CVE-2017-6470)

- capability ±æÀ̸¦ ´Ù·ê ¶§ epan/dissectors/packet-wsp.c ÆÄÀÏ dissect_wsp_common() ÇÔ¼öÀÇ WSP¿¡ ¹«ÇÑ ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6471)

- epan/dissectors/packet-rtmpt.c ÆÄÀÏ dissect_rtmpt_common() ÇÔ¼öÀÇ RTMPT Çؼ®±â¿¡¼­ ÀϺΠÀÔ·Â °ª È®ÀÎÀ» À߸ø ÇØ ¹«ÇÑ ·çÇÁ »óÅ°¡ ¹ß»ýÇÑ´Ù. (CVE-2017-6472)

- wiretap/k12.c ÆÄÀÏ process_packet_data() ÇÔ¼ö¿¡¼­ ÀϺΠÀÔ·Â °ª È®ÀÎÀ» À߸ø ÇØ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-6473)

- wiretap/netscaler.c ÆÄÀÏÀÇ nstrace_read_v30(), nstrace_read_v20(), nstrace_read_v10() ÇÔ¼öÀÇ NetScaler ÆÄÀÏ Æļ­¿¡ ¹«ÇÑ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6474)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.wireshark.org/security/wnpa-sec-2017-03.html
https://www.wireshark.org/security/wnpa-sec-2017-04.html
https://www.wireshark.org/security/wnpa-sec-2017-05.html
https://www.wireshark.org/security/wnpa-sec-2017-07.html
https://www.wireshark.org/security/wnpa-sec-2017-08.html
https://www.wireshark.org/security/wnpa-sec-2017-09.html
https://www.wireshark.org/security/wnpa-sec-2017-10.html
https://www.wireshark.org/security/wnpa-sec-2017-11.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Wireshark 2.0.11 ÀÌÀü 2.0.x ¹öÀü
Microsoft Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ Wireshark À¥ »çÀÌÆ®ÀÎ http://www.wireshark.org/download/win32/all-versions/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â WiresharkÀÇ °¡Àå ÃֽŠ¹öÀü(2.0.11 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2017-6467,CVE-2017-6468,CVE-2017-6469,CVE-2017-6470,CVE-2017-6471,CVE-2017-6472,CVE-2017-6473,CVE-2017-6474 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)