Ãë¾àÁ¡ID |
50119 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ Wireshark 2.0.12 ÀÌÀü 2.0.x ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
- Ư¼öÇÑ Ä¸ÃÄ ÆÄÀÏÀ» ´Ù·ê ¶§, wiretap/netscaler.c ÆÄÀÏÀÇ NetScaler file parser¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7700)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-bgp.c ÆÄÀÏÀÇ BGP Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7701)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-wbxml.c ÆÄÀÏÀÇ WBXML Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7702)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-imap.c ÆÄÀÏÀÇ IMAP Çؼ®±â ¾È¿¡ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ÇÁ·Î±×·¥ Ãæµ¹À» À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7703)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-dof.c ÆÄÀÏÀÇ DOF Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. ÇØ´ç À̽´´Â 2.2.x ¹öÀü¿¡¼¸¸ Àû¿ëµÈ´Ù. (CVE-2017-7704)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-rpcrdma.c ÆÄÀÏÀÇ RPC over RDMA Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7705)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-sigcomp.c ÆÄÀÏÀÇ SIGCOMP Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7745)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-slsk.c ÆÄÀÏÀÇ dissect_slsk_pdu() ÇÔ¼öÀÇ SLSK Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7746)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀû ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-packetbb.c ÆÄÀÏÀÇ dissect_pbb_addressblock() ÇÔ¼öÀÇ PacketBB Çؼ®±â ¾È¿¡ °æ°è °ª Àб⠿À·ù°¡ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ÇÁ·Î±×·¥ Ãæµ¹À» À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7747)
- Ư¼öÇÑ ÆÐŶ ¶Ç´Â ÃßÀü ÆÄÀÏÀ» ´Ù·ê ¶§, epan/dissectors/packet-wsp.c ÆÄÀÏÀÇ WSP Çؼ®±â ¾È¿¡ ¹«ÇÑ·çÇÁ Á¶°ÇÀÌ Á¸ÀçÇÑ´Ù. ÀÎÁõ ¹ÞÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°´Â °úµµÇÑ CPU ÀÚ¿ø ¼Òºñ¸¦ ¾ß±â½ÃÅ°±â À§ÇÏ¿©, ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2017-7748)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: https://www.wireshark.org/docs/relnotes/wireshark-2.0.12.html https://www.wireshark.org/docs/relnotes/wireshark-2.2.6.html https://www.wireshark.org/security/wnpa-sec-2017-12.html https://www.wireshark.org/security/wnpa-sec-2017-13.html https://www.wireshark.org/security/wnpa-sec-2017-14.html https://www.wireshark.org/security/wnpa-sec-2017-15.html https://www.wireshark.org/security/wnpa-sec-2017-16.html https://www.wireshark.org/security/wnpa-sec-2017-17.html https://www.wireshark.org/security/wnpa-sec-2017-18.html https://www.wireshark.org/security/wnpa-sec-2017-19.html https://www.wireshark.org/security/wnpa-sec-2017-20.html https://www.wireshark.org/security/wnpa-sec-2017-21.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Wireshark 2.0.12 ÀÌÀü 2.0.x ¹öÀü Microsoft Windows ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Wireshark À¥ »çÀÌÆ®ÀÎ http://www.wireshark.org/download/win32/all-versions/¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WiresharkÀÇ °¡Àå ÃֽŠ¹öÀü(2.0.12 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2017-7700,CVE-2017-7701,CVE-2017-7702,CVE-2017-7703,CVE-2017-7704,CVE-2017-7705,CVE-2017-7745,CVE-2017-7746,CVE-2017-7747,CVE-2017-7748 (CVE) |
°ü·Ã URL |
97627,97628,97630,97631,97632,97633,97634,97635,97636,97638 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|