°øÁö»çÇ×
Á¦¸ñ: [º¸¾È°øÁö] MS Internet Explorer ¿ø°ÝÄÚµå ½ÇÇà ½Å±Ô Ãë¾àÁ¡ ÁÖÀÇ ±Ç°í
µî·ÏÀÚ : ZINTADM1 Á¶È¸ : 4915 µî·ÏÀÏ : 2013-01-03 10:15:20

'13³â 1¿ù 1ÀÏ ¾÷µ¥ÀÌÆ® ³»¿ë

- '12³â 12¿ù30ÀÏ ¹ß°ßµÈ MS º¸¾ÈÃë¾àÁ¡¿¡ ´ëÇÑ ±ÇÀå¹æ¾È ¾÷µ¥ÀÌÆ®

 

 

°³¿ä

  • ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®(ÀÌÇÏ MS)ÀÇ Internet Explorer¿¡¼­ ¿ø°ÝÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ ½Å±Ô Ãë¾àÁ¡ÀÌ ¹ß°ßµÊ [1]
  • ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®´Â ¾ÆÁ÷ ¹ßÇ¥µÇÁö ¾Ê¾ÒÀ¸³ª, Ãë¾àÁ¡À» ¾Ç¿ëÇÑ °ø°Ý ½Ãµµ°¡ ÇØ¿Ü¿¡¼­ È®ÀÎµÇ¾î »ç¿ëÀÚÀÇ ÁÖÀÇ°¡ ƯÈ÷ ¿ä±¸µÊ [2]

¼³¸í

  • MSÀÇ Internet Explorer¿¡¼­ »ç¿ëµÇ´Â mshtml CDwnBindInfo ¿ÀºêÁ§Æ®¿¡¼­ use-after-free Ãë¾àÁ¡ÀÌ ¹ß»ýÇÔ
  • ÇØ´ç Ãë¾àÁ¡À» ¾Ç¿ëÇÑ °ø°ÝÀº ¾Ç¼ºÄÚµå ½ÇÇà ¹× À©µµ¿ìÁîÀÇ º¸¾È±â´É ¿ìȸ¸¦ À§ÇØ Adobe Flash ¹× Java°¡ ÀÌ¿ëµÊ

ÇØ´ç ½Ã½ºÅÛ

  • ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
    • Internet Explorer 6
    • Internet Explorer 7
    • Internet Explorer 8
  • ¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
    • Internet Explorer 9
    • Internet Explorer 10

±ÇÀå ¹æ¾È

  • ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾ÒÀ½
  • Ãë¾àÁ¡À¸·Î ÀÎÇÑ À§ÇùÀ» °æ°¨½ÃÅ°±â À§ÇØ ´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ±ÇÀåÇÔ[7]
    - MS ȨÆäÀÌÁö ¡°Fix it for me¡±¼½¼ÇÀÇ ¡°Microsoft Fix it 50971¡±¸¦ ´Ù¿î·Îµå ÈÄ ¼³Ä¡
    ¡Ø ¿ø»óÅ·Πº¹±¸Çϱâ À§Çؼ­´Â ¡°Microsoft Fix it 50972¡±À» Àû¿ë
    fix2 fix1
  • KrCERT/CC¿Í MS º¸¾È¾÷µ¥ÀÌÆ® »çÀÌÆ®¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÏ¿© ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ® ¹ßÇ¥ ½Ã ½Å¼ÓÈ÷ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϰųª ÀÚµ¿¾÷µ¥ÀÌÆ®¸¦ ¼³Á¤
    ¡Ø ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤ ¹æ¹ý: ½ÃÀÛ¡æÁ¦¾îÆǡ溸¾È¼¾ÅÍ¡æÀÚµ¿¾÷µ¥ÀÌÆ®¡æÀÚµ¿(±ÇÀå) ¼±ÅÃ
  • Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇÏ¿© »ç¿ëÀÚ´Â ´ÙÀ½°ú °°Àº »çÇ×À» ÁؼöÇؾßÇÔ
    - ½Å·ÚµÇÁö ¾Ê´Â À¥ »çÀÌÆ®ÀÇ ¹æ¹® ÀÚÁ¦
    - »ç¿ëÇÏ°í ÀÖ´Â ¹é½ÅÇÁ·Î±×·¥ÀÇ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ À¯ÁöÇÏ°í, ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ­
    - Ãâó°¡ ºÒºÐ¸íÇÑ À̸ÞÀÏÀÇ ¸µÅ© Ŭ¸¯Çϰųª ÷ºÎÆÄÀÏ ¿­¾îº¸±â ÀÚÁ¦

¿ë¾î Á¤¸®

  • Use After Free Ãë¾àÁ¡ : ¼ÒÇÁÆ®¿þ¾î ±¸Çö ½Ã µ¿Àû ȤÀº Á¤ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸®¸¦ ÇØÁ¦ÇßÀ½¿¡µµ ºÒ±¸ÇÏ°í À̸¦ °è¼Ó ÂüÁ¶(»ç¿ë)ÇÏ¿© ¹ß»ýÇÏ´Â Ãë¾àÁ¡

±âŸ ¹®ÀÇ»çÇ×

  • Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118

[Âü°í»çÀÌÆ®]

[1] http://technet.microsoft.com/security/advisory/2794220
[2] http://blog.fireeye.com/research/2012/12/council-foreign-relations-water-hole-attack-details.html
[3] http://support.microsoft.com/kb/2458544
[4] http://go.microsoft.com/fwlink/?LinkID=200220&clcid=0x409
[5] http://support.microsoft.com/kb/240797
[6] http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html#disable

[7] http://support.microsoft.com/kb/2794220


[À­±Û] [¸ñ·ÏÀ¸·Î] [¾Æ·§±Û]