Ãë¾àÁ¡ID |
50118 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ Wireshark 2.2.5 ÀÌÀü 2.2.x ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- wiretap/netscaler.c ÆÄÀÏÀÇ nstrace_read_v20(), nstrace_read_v30() ÇÔ¼öÀÇ Netscaler ÆÄÀÏ Æļ¿¡¼ ÀԷ°©À» ´Ù·ê ¶§ ¹«ÇÑ ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6467)
- wiretap/netscaler.c ÆÄÀÏÀÇ ¿©·¯ ÇÔ¼ö¿¡¼ ·¹ÄÚµå ±æÀ̸¦ ´Ù·ê ¶§ °æ°è °ª ÃÊ°ú Àб⠿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6468)
- epan/dissectors/packet-ldss.c ÆÄÀÏÀÇ dissect_ldss_transfer() ÇÔ¼ö¿¡¼ ¸Þ¸ð¸® ÇÒ´ç ¿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6469)
- ŸÀÓ ½ºÅÆÇÁ¸¦ ´Ù·ê ¶§ epan/dissectors/packet-iax2.c ÆÄÀÏÀÇ iax2_add_ts_fields() ÇÔ¼ö¿¡¼ ¹«ÇÑ ·çÇÁ »óÅ°¡ ¹ß»ýÇÑ´Ù. (CVE-2017-6470)
- capability ±æÀ̸¦ ´Ù·ê ¶§ epan/dissectors/packet-wsp.c ÆÄÀÏ dissect_wsp_common() ÇÔ¼öÀÇ WSP¿¡ ¹«ÇÑ ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6471)
- epan/dissectors/packet-rtmpt.c ÆÄÀÏ dissect_rtmpt_common() ÇÔ¼öÀÇ RTMPT Çؼ®±â¿¡¼ ÀϺΠÀÔ·Â °ª È®ÀÎÀ» À߸ø ÇØ ¹«ÇÑ ·çÇÁ »óÅ°¡ ¹ß»ýÇÑ´Ù. (CVE-2017-6472)
- wiretap/k12.c ÆÄÀÏ process_packet_data() ÇÔ¼ö¿¡¼ ÀϺΠÀÔ·Â °ª È®ÀÎÀ» À߸ø ÇØ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2017-6473)
- wiretap/netscaler.c ÆÄÀÏÀÇ nstrace_read_v30(), nstrace_read_v20(), nstrace_read_v10() ÇÔ¼öÀÇ NetScaler ÆÄÀÏ Æļ¿¡ ¹«ÇÑ·çÇÁ »óÅ°¡ Á¸ÀçÇÑ´Ù. (CVE-2017-6474)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: https://www.wireshark.org/security/wnpa-sec-2017-03.html https://www.wireshark.org/security/wnpa-sec-2017-04.html https://www.wireshark.org/security/wnpa-sec-2017-05.html https://www.wireshark.org/security/wnpa-sec-2017-07.html https://www.wireshark.org/security/wnpa-sec-2017-08.html https://www.wireshark.org/security/wnpa-sec-2017-09.html https://www.wireshark.org/security/wnpa-sec-2017-10.html https://www.wireshark.org/security/wnpa-sec-2017-11.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Wireshark 2.2.5 ÀÌÀü 2.2.x ¹öÀü Microsoft Windows ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Wireshark À¥ »çÀÌÆ®ÀÎ http://www.wireshark.org/download/win32/all-versions/¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WiresharkÀÇ °¡Àå ÃֽŠ¹öÀü(2.2.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2017-6467,CVE-2017-6468,CVE-2017-6469,CVE-2017-6470,CVE-2017-6471,CVE-2017-6472,CVE-2017-6473,CVE-2017-6474 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|