English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50203
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý Windows È£½ºÆ®¿¡ ¼³Ä¡µÈ WiresharkÀÇ ¹öÀüÀº 2.4.11 ÀÌÀüÀÇ 2.4.xÀÔ´Ï´Ù. ÇØ´ç ¹öÀüÀº ´ÙÁßÃë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.

- MMSE dissector´Â ¹«ÇÑ ·çÇÁ¿¡ ºüÁú ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº epan / dissectors / packet-mmse.c¿¡¼­ ±æÀÌ ¿À¹öÇ÷θ¦ ¹æÁöÇÔÀ¸·Î½á ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-8540)

- LBMPDM dissector°¡ Ãæµ¹ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ ¿ø°Ý °ø°ÝÀÚ´Â ÆÐŶ ¹üÀ§ ¸Þ¸ð¸®º¸´Ù ÀÓÀÇÀÇ ¸Þ¸ð¸® À§Ä¡¿¡ ÀÓÀÇÀÇ µ¥ÀÌÅ͸¦ ¾µ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº epan / dissectors / packet-lbmpdm.c¿¡¼­ ƯÁ¤ À½¼ö °ªÀ» Çã¿ëÇÏÁö ¾ÊÀ½À¸·Î½á ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-19623)

- PVFS dissector°¡ Ãæµ¹ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº epan / dissectors / packet-pvfs2.c¿¡¼­ NULL Æ÷ÀÎÅÍ ¿ª ÂüÁ¶¸¦ ¹æÁöÇÔÀ¸·Î½á ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-19624)

- dissector ¿£ÁøÀÌ ºÎ¼­ Áú ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº epap / tvbuff_composite.c¿¡¼­ Èü ±â¹Ý ¹öÆÛ ¿À¹ö Àб⸦ ¹æÁöÇÔÀ¸·Î½á ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-19625)

- DCOM dissector°¡ °íÀ峯 ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº epan / dissectors / packet-dcom.c¿¡¼­ '\ 0'Á¾·á¸¦ Ãß°¡ÇÔÀ¸·Î½á ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-19626)

- IxVeriWave ÆÄÀÏ Æļ­°¡ Ãæµ¹ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ¹öÆÛ °æ°è¸¦ Á¶Á¤ÇÏ¿© wiretap / vwr.c¿¡¼­ ÇØ°áµÇ¾ú½À´Ï´Ù. (CVE-2018-19627) "

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.wireshark.org/docs/relnotes/wireshark-2.4.11.html
https://www.wireshark.org/security/wnpa-sec-2018-51.html
https://www.wireshark.org/security/wnpa-sec-2018-52.html
https://www.wireshark.org/security/wnpa-sec-2018-53.html
https://www.wireshark.org/security/wnpa-sec-2018-54.html
https://www.wireshark.org/security/wnpa-sec-2018-55.html
https://www.wireshark.org/security/wnpa-sec-2018-56.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Wireshark 2.4.11 ÀÌÀü 2.4.x ¹öÀü
Microsoft Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ Wireshark À¥ »çÀÌÆ®ÀÎ http://www.wireshark.org/download/win32/all-versions/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â WiresharkÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.11 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2018-19622,CVE-2018-19623,CVE-2018-19624,CVE-2018-19625,CVE-2018-19626,CVE-2018-19627 (CVE)
°ü·Ã URL 106051 (SecurityFocus)
°ü·Ã URL (ISS)