๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๋ฐ˜์‘ํ˜•

์ „์ฒด ๊ธ€424

[Linux] AdoptOpenJDK Install ์ง€๊ธˆ๊นŒ์ง€ ์‚ฌ์šฉ์žํ•œํ…Œ ๋„๋ฆฌ ์‚ฌ์šฉ ๋˜๊ณ  ์žˆ๋˜, OpenJDK๊ฐ€ ๋งŽ์€ ๋‚ด์šฉ ๋์— Version 11 ๋ถ€ํ„ฐ๋Š” ์œ ๋ฃŒํ™”๊ฐ€ ๊ฒฐ์ •์ด ๋˜์—ˆ๋‹ค. ๋ฌผ๋ก  ๊ธฐ์กด Version ํ˜น์€ ๋น„์˜๋ฆฌ ๋ชฉ์ ์œผ๋กœ ์‚ฌ์šฉ์‹œ 2020๋…„ 12์›”๊นŒ์ง€๋Š” ์—…๋ฐ์ดํŠธ๊ฐ€ ๊ฐ€๋Šฅํ•œ ๊ฒƒ์œผ๋กœ ํ™•์ธ ๋˜์—ˆ๋‹ค. ๋‹ค๋งŒ, JAVA(JDK)๋ฅผ ์ง€์›ํ•˜๋Š” ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ Version์ด ์˜ฌ๋ผ๊ฐ์œผ๋กœ์„œ ์š”๊ตฌํ•˜๋Š” JAVA Version๋„ ์˜ฌ๋ผ๊ฐ€๊ณ  ์žˆ๋‹ค. ๊ทธ๋ž˜์„œ OpenJDK๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉ๊ฐ€๋Šฅํ•œ ๋งŽ์€ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ๋‚˜์˜ค๊ณ  ์žˆ๋‹ค. Azul Zulu / Amazon Corretto / AdoptOpenJDK / ๊ธฐํƒ€ ๋“ฑ๋“ฑ ์ด์ค‘ ์ด๋ฒˆ์—๋Š” AdoptOpenJDK๋ฅผ ์ด์šฉํ•˜์—ฌ ์„ค์น˜ ๋ฐ ๋ฒ„์ „ ํ™•์ธ ๋ฐฉ๋ฒ• ๊นŒ์ง€ ์•Œ์•„ ๋ณด๋„๋ก ํ•˜๊ฒ ๋‹ค. ํ•ด๋‹น ์„ค๋ช…์€ CentOS 8 / AdoptOpenJDK 11 ๋กœ ํ•˜๊ฒ .. 2020. 6. 19.
[Linux] Chrony??? NTP vs Chrony ์–ผ๋งˆ์ „ ํ…Œ์ŠคํŠธ ์„œ๋ฒ„์— CentOS 8 ์„ ์„ค์น˜๋งŒ ํ•ด๋†“๊ณ , ์ƒ๊ฐํ•˜๊ณ  ์žˆ๋Š” ๋ถ€๋ถ„์„ ์ง„ํ–‰ํ•˜์ง€ ๋ชปํ•˜๊ณ  ํ•œ๋™ํ•œ ๊ณ„์† ๋ฐฉ์น˜ํ•˜๊ณ  ์žˆ์—ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‹ค๊ฐ€ ๊ฐ„๋‹จํžˆ ํ™•์ธํ•  ๋ถ€๋ถ„์ด ์žˆ์–ด์„œ ํ…Œ์ŠคํŠธ ์„œ๋ฒ„์— ์ ‘์† ํ•˜๊ณ  ํ™•์ธํ•  ๋ถ€๋ถ„์„ ๋‹ค ํ™•์ธํ•˜๊ณ ์„  ์šฐ์—ฐํžˆ date ๋ช…๋ น์–ด๋ฅผ ์ณค๋Š”๋ฐ ํ˜„์žฌ ์‹œ๊ฐ„๊ณผ ๋‹ค๋ฅด๊ฒŒ ์„ค์ •์ด ๋˜์–ด์žˆ์Œ์„ ํ™•์ธํ•˜์˜€๋‹ค. ์•„๋ฌด ์ƒ๊ฐ ์—†์Œ ntpd ๊ตฌ๋™ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•˜์˜€๋Š”๋ฐ ntp๊ฐ€ ๊ตฌ๋™์„ ํ•˜์ง€ ์•Š๊ณ  ์žˆ์–ด ๋‹นํ™ฉ์„ ํ•˜์˜€๊ณ  ๊ทธ๋Ÿฌ๋ฉด์„œ ์„œ๋ฒ„ ์‹œ๊ฐ„ ๋™๊ธฐํ™” ๊ด€๋ จํ•˜์—ฌ ํ™•์ธํ•˜๊ฒŒ ๋˜์—ˆ๋‹ค. ๋จผ์ € RHEL / CentOS 8 ๋ถ€ํ„ฐ๋Š” ntpd ๊ฐ€ ์ง€์›์ด ์ข…๋ฃŒ ๋˜๊ณ  ์‹œ๊ฐ„ ๋™๊ธฐํ™” ๊ด€๋ จํ•˜์—ฌ chronyd ๊ฐ€ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉ ๋œ๋‹ค. $ ps -ef | grep chronyd chrony 1640 1 0 5์›”31 ? 00:00:00 /usr/sbin/chrony.. 2020. 6. 18.
[๋ณด์•ˆ๊ณต์ง€] VLC Media Player 3.0.11 ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์  ํŒจ์น˜ VideoLan์—์„œ ์œˆ๋„์šฐ, ๋งฅ, ๋ฆฌ๋ˆ…์Šค์šฉ VLC ํ”Œ๋ ˆ์ด์–ด 3.0.11์„ ๊ณต๊ฐœํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด ํŒจ์น˜๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ ์›๊ฒฉ์œผ๋กœ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ VLC ํ”„๋กœ๊ทธ๋žจ์„ ์ถฉ๋Œ์‹œํ‚ฌ ์ˆ˜ ์žˆ์—ˆ๋˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ํฌํ•จํ•œ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•˜๊ณ  ๊ธฐํƒ€ ์‚ฌํ•ญ์„ ๊ฐœ์„ ํ•ฉ๋‹ˆ๋‹ค.์ด ์ทจ์•ฝ์ ์€ CVE-2020-13428๋กœ ๋“ฑ๋ก๋˜์—ˆ์œผ๋ฉฐ “VLC H26X packetizer ๋‚ด ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ” ์ทจ์•ฝ์ ์œผ๋กœ ์•…์šฉ๋  ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๊ฐ€ ์‚ฌ์šฉ์ž์™€ ๋™์ผํ•œ ๋ณด์•ˆ ์ˆ˜์ค€์œผ๋กœ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๋„๋ก ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.VideoLan์˜ ๋ณด์•ˆ ๊ณต์ง€์— ๋”ฐ๋ฅด๋ฉด, ์ด ์ทจ์•ฝ์ ์€ ํ”ผํ•ด์ž๊ฐ€ VLC๋กœ ํŠน์ˆ˜ ์ œ์ž‘๋œ ํŒŒ์ผ์„ ์˜คํ”ˆํ•˜๋„๋ก ์†์ด๋Š” ๋ฐฉ์‹์œผ๋กœ ์•…์šฉ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.VideoLan์€ ์ด ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ํ”Œ๋ ˆ์ด์–ด๊ฐ€ ์ถฉ๋Œ๋  ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์ง€๋งŒ, ์‚ฌ์šฉ์ž์™€ ๋™์ผํ•œ ๋ณด์•ˆ ์ˆ˜์ค€์œผ๋กœ ์›๊ฒฉ ๋ช…๋ น ์‹คํ–‰์ด ๊ฐ€๋Šฅํ•  ์ˆ˜๋„.. 2020. 6. 18.
[MySQL] CentOS 8 Mysql Install ํ•˜๊ธฐ CentOS 8 ์‹œ์Šคํ…œ์— Mysql์„ ์„ค์น˜ํ•ด๋ณด๋„๋ก ํ•˜์ž. 1. yum ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด "mysql-server" ์„ค์น˜ [root@localhost ~]$ yum install mysql-server CentOS-8 - AppStream 8.4 kB/s | 4.3 kB 00:00 CentOS-8 - Base 7.3 kB/s | 3.9 kB 00:00 CentOS-8 - Extras 2.5 kB/s | 1.5 kB 00:00 Dependencies resolved. ====================================================================================================== Package Arch Version Repository Siz.. 2020. 6. 13.
[MySQL] Mysql ERROR 1819 (HY000): Your password does not satisfy the current policy requirements ํ•ด๊ฒฐ ํ•˜๊ธฐ MySQL์„ ์ฒ˜์Œ ์„ค์น˜ ํ›„ ์‹ ๊ทœ ๊ณ„์ •์„ ๋“ฑ๋ก์„ ํ•˜๋ ค๊ณ  ํ• ๋•Œ, "ERROR 1819 (HY000): Your password does not satisfy the current policy requirements" ์™€ ๊ฐ™์€ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. mysql> CREATE USER 'test'@'%' IDENTIFIED BY '12test34'; ERROR 1819 (HY000): Your password does not satisfy the current policy requirements mysql> select Host, User from user; +-----------+------------------+ | Host | User | +-----------+------------------+ .. 2020. 6. 13.
[KISA] UPnP ์ทจ์•ฝ์  ์ฃผ์˜ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o OCF์˜ UPnP ํ”„๋กœํ† ์ฝœ์—์„œ ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ o ๊ณต๊ฒฉ์ž๋Š” ํ•ด๋‹น ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋“ฑ์˜ ํ”ผํ•ด๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ์˜ํ–ฅ๋ฐ›๋Š” ์ œํ’ˆ ๋˜๋Š” ๊ธฐ๊ธฐ๋ฅผ ์ด์šฉ ์ค‘์ธ ์‚ฌ์šฉ์ž์˜ ์ฃผ์˜ ํ•„์š” โ€ป OCF(Open Connectivity Foundation) : ๋„คํŠธ์›Œํฌ ๊ธฐ๊ธฐ ๊ฐ„ ํ†ต์‹ ์„ ์œ„ํ•ด ํ‘œ์ค€ ํ†ต์‹  ํ”Œ๋žซํผ์„ ์ œ๊ณตํ•˜๋Š” ํ‘œ์ค€ํ™” ๊ธฐ๊ตฌ โ€ป UPnP(Universal Plug and Play) : ํŠน๋ณ„ํ•œ ์„ค์ •์ด๋‚˜ ์„ค์น˜ ์—†์ด ๋‹ค์–‘ํ•œ ๋„คํŠธ์›Œํฌ ๊ธฐ๊ธฐ ๊ฐ„ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ๋„๋ก ์„ค๊ณ„๋œ ํ”„๋กœํ† ์ฝœ โ–ก ์ฃผ์š” ๋‚ด์šฉ o UPnP SUBSCRIBE ํ•จ์ˆ˜์˜ ์ฝœ๋ฐฑ ํ—ค๋” ๊ฐ’์ด ์ž„์˜ ์กฐ์ž‘์ด ๊ฐ€๋Šฅํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋ฐ ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ์ทจ์•ฝ์ (CVE-2020-12695) [1][2] โ–ก ์˜ํ–ฅ๋ฐ›๋Š” ์ œํ’ˆ(6.10์ผ ๊ธฐ์ค€) ๊ตฌ๋ถ„ ์ œ์กฐ์‚ฌ ๋ฒ„์ „ .. 2020. 6. 12.
[KISA] Zoom ์ทจ์•ฝ์  ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o Zoom ็คพ๋Š” ์ž์‚ฌ ์ œํ’ˆ์˜ ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ณต๊ฐœ o ๊ณต๊ฒฉ์ž๋Š” ํ•ด๋‹น ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ์›๊ฒฉ์ฝ”๋“œ ์‹คํ–‰ ๋“ฑ์˜ ํ”ผํ•ด๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ํ•ด๋‹น ์ œํ’ˆ์„ ์‚ฌ์šฉํ•˜๋Š” ์ด์šฉ์ž๋“ค์€ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ์ฃผ์š” ๋‚ด์šฉ o Zoom ํด๋ผ์ด์–ธํŠธ์—์„œ ์• ๋‹ˆ๋ฉ”์ด์…˜ GIF ๋ฉ”์‹œ์ง€์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๊ณต๊ฒฉ์ž๊ฐ€ ์•…์„ฑํŒŒ์ผ์„ ํ”ผํ•ด์ž์˜ ์‹œ์Šคํ…œ์— ์ €์žฅํ•  ์ˆ˜ ์žˆ๋Š” ์ž„์˜ ํŒŒ์ผ ์“ฐ๊ธฐ ์ทจ์•ฝ์ (CVE-2020-6109) [1] o Zoom ํด๋ผ์ด์–ธํŠธ์—์„œ ํŠน์ • ๋ฉ”์‹œ์ง€์— ๋Œ€ํ•œ ์ฒ˜๋ฆฌ๊ฐ€ ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ์ž„์˜ ํŒŒ์ผ ์“ฐ๊ธฐ ์ทจ์•ฝ์ (CVE-2020-6110) [2] โ–ก ์˜ํ–ฅ๋ฐ›๋Š” ์ œํ’ˆ o Zoom Client 4.6.10 โ–ก ํ•ด๊ฒฐ ๋ฐฉ์•ˆ o ์ทจ์•ฝ์ ์ด ํ•ด๊ฒฐ๋œ ๋ฒ„์ „(4.6.12 ์ด์ƒ ๋ฒ„์ „)์œผ๋กœ ์—…๋ฐ์ดํŠธ ์ˆ˜ํ–‰ [3] โ–ก ๊ธฐํƒ€ ๋ฌธ์˜์‚ฌํ•ญ.. 2020. 6. 12.
[Linux] Linux(๋ฆฌ๋ˆ…์Šค)์—์„œ CPU ์ •๋ณด ํ™•์ธ ๋ฐฉ๋ฒ• ๊ฐ„ํ˜น ์‚ฌ์šฉ์ค‘์ธ ์‹œ์Šคํ…œ์˜ CPU ์ •๋ณด(๋ชจ๋ธ, ์ฝ”์–ด ๊ฐฏ์ˆ˜, ์ฝ”์–ด ์†๋„๋“ฑ)์— ๋Œ€ํ•ด์„œ ํ™•์ธ์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. Linux(๋ฆฌ๋ˆ…์Šค) OS์—์„œ CPU ์ •๋ณด๋ฅผ ํ™•์ธ ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด๋„๋ก ํ•˜์ž. 1. /proc/cpuinfo Linux(๋ฆฌ๋ˆ…์Šค)์—์„œ ์ œ์ผ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” "/proc/cpuinfo" ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด์„œ ์ž์„ธํ•˜๊ฒŒ ์•Œ์•„๋ณด๋„๋ก ํ•˜์ž. ์ œ ํ…Œ์ŠคํŠธ ์„œ๋ฒ„์˜ ์ •๋ณด๋Š” "i5-7500 3.40GHz" ์ด๋ฉฐ, ๊ฐ์ข… CPU์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋‹ค. 1.1 ํ”„๋กœ์„ธ์Šค ๊ฐฏ์ˆ˜ ํ•ด๋‹น ๋‚ด์šฉ์— ๋Œ€ํ•ด์„œ๋Š” ์•„๋ž˜์™€ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ๊ตฌํ•  ์ˆ˜ ์žˆ๋‹ค. $ cat /proc/cpuinfo | grep processor | wc -l 4 1.2 ์ฝ”์–ด ๊ฐฏ์ˆ˜ ํ•ด๋‹น ๋‚ด์šฉ์— ๋Œ€ํ•ด์„œ๋Š” ์•„๋ž˜์™€ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ๊ตฌํ•  ์ˆ˜ ์žˆ๋‹ค. $ cat /proc.. 2020. 6. 7.
[KISA] Apple ์ œํ’ˆ๊ตฐ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o Apple็คพ๋Š” ์ž์‚ฌ ์ œํ’ˆ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋ฐœํ‘œ[1] o ๊ณต๊ฒฉ์ž๋Š” ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์—ฌ ํ”ผํ•ด๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ํ•ด๋‹น Apple ์ œํ’ˆ์„ ์‚ฌ์šฉํ•˜๋Š” ์ด์šฉ์ž๋“ค์€ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ์„ค๋ช… o MacOS, tvOS, watchOS, iOS, iPadOS์—์„œ ๋ฉ”๋ชจ๋ฆฌ ์ฒ˜๋ฆฌ๊ฐ€ ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ์ž„์˜์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ (CVE-2020-9859) [2][3][4][5] โ–ก ์˜ํ–ฅ์„ ๋ฐ›๋Š” ๋ฒ„์ „ ๋ฐ ์ œํ’ˆ o MacOS - High Sierra 10.13.6 - Catalina 10.15.5 o tvOS : Apple TV 4K ๋ฐ TV HD o watchOS : ์• ํ”Œ ์›Œ์น˜ ์‹œ๋ฆฌ์ฆˆ 1 ๋ฐ ์ดํ›„ ๋ชจ๋ธ o iOS ๋ฐ iPadOS - iOS : iPhone 6s ๋ฐ ์ดํ›„ ๋ชจ๋ธ - iP.. 2020. 6. 7.
[KISA] Cisco ์ œํ’ˆ ์ทจ์•ฝ์  ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o Cisco็คพ๋Š” ์ž์‚ฌ ์ œํ’ˆ์˜ ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ณต์ง€ [1] o ๊ณต๊ฒฉ์ž๋Š” ํ•ด๋‹น ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ์›๊ฒฉ์ฝ”๋“œ ์‹คํ–‰ ๋“ฑ์˜ ํ”ผํ•ด๋ฅผ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ํ•ด๋‹น ์ œํ’ˆ์„ ์‚ฌ์šฉํ•˜๋Š” ์ด์šฉ์ž๋“ค์€ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ์ฃผ์š” ๋‚ด์šฉ o Cisco IOx์—์„œ ์ธ์ฆ ํ† ํฐ ์š”์ฒญ์— ๋Œ€ํ•œ ์ฒ˜๋ฆฌ๊ฐ€ ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ๊ถŒํ•œ์ƒ์Šน ์ทจ์•ฝ์ (CVE-2020-3227) [2] o Cisco IOS Software์—์„œ ํŒจํ‚ท์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ๋ช…๋ น์–ด ์‚ฝ์ž… ์ทจ์•ฝ์ (CVE-2020-3205) [3] o Cisco IOS Software์—์„œ ํŒจํ‚ท์˜ ํŠน์ • ๊ฐ’์— ๋Œ€ํ•œ ๊ฒฝ๊ณ„๊ฐ’ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ์›๊ฒฉ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ (CVE-2020-3198) ๋“ฑ 2๊ฐœ [4] โ–ก ์˜ํ–ฅ ๋ฐ›๋Š” ์ œํ’ˆ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ o ์ฐธ๊ณ  ์‚ฌ์ดํŠธ์— .. 2020. 6. 7.
[๋ณด์•ˆ๊ณต์ง€] Apache Tomcat ์ทจ์•ฝ์  ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ (KISA) โ–ก ๊ฐœ์š” o Apache Tomcat์—์„œ ์‹ ๊ทœ ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋ฐœํ‘œ[1] o ์ทจ์•ฝํ•œ ๋ฒ„์ „์„ ์‚ฌ์šฉ ์ค‘์ธ ์„œ๋ฒ„์˜ ๋‹ด๋‹น์ž๋Š” ์ œ์กฐ์‚ฌ์˜ ํ™ˆํŽ˜์ด์ง€๋ฅผ ์ฐธ๊ณ ํ•˜์—ฌ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ€ป Apache Tomcat : ์˜คํ”ˆ์†Œ์Šค ๊ธฐ๋ฐ˜ ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์„œ๋ฒ„ โ–ก ์„ค๋ช… o Apache Tomcat์—์„œ ํŠน์ • ์กฐ๊ฑด*์ด ์„ฑ๋ฆฝ๋˜๋Š” ๊ฒฝ์šฐ, ๊ณต๊ฒฉ์ž์˜ ์•…์„ฑ ์š”์ฒญ ๋ฉ”์‹œ์ง€๊ฐ€ ์—ญ์ง๋ ฌํ™”๋˜์–ด ๋ฐœ์ƒํ•˜๋Š” ์ž„์˜์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ (CVE-2020-9484) [1] * ํŠน์ •์กฐ๊ฑด 1. ํ†ฐ์บฃ ์„œ๋ฒ„์˜ PersistenceManager๊ฐ€ Filestore๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ์„ค์ •๋œ ๊ฒฝ์šฐ 2. PersistenceManager์˜ sessionAttributeValueClassNameFilter ํ•ญ๋ชฉ์ด "null"๋กœ ์„ค์ •๋˜๊ฑฐ๋‚˜ ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ๊ณตํ•œ ๊ฐ์ฒด์˜ ๊ฒ€์ฆ์ด.. 2020. 5. 26.
[๋ณด์•ˆ๊ณต์ง€] BIND DNS ์ทจ์•ฝ์  ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ (KISA) โ–ก ๊ฐœ์š” o ISC(Internet Systems Consortium)๋Š” BIND DNS์—์„œ ์„œ๋น„์Šค ๊ฑฐ๋ถ€๋ฅผ ์œ ๋ฐœํ•˜๋Š” ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋ฐœํ‘œ o ์˜ํ–ฅ๋ฐ›๋Š” ๋ฒ„์ „์˜ ์‚ฌ์šฉ์ž๋Š” ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ํ”ผํ•ด๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ์ด์šฉ์ž๋“ค์€ ์•„๋ž˜ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ์„ ์ฐธ์กฐํ•˜์—ฌ ์กฐ์น˜ ๊ถŒ๊ณ  โ–ก ์„ค๋ช… o BIND ์„œ๋ฒ„์—์„œ ์žฌ๊ท€(Recursive) ์ฟผ๋ฆฌ๋ฅผ ์ˆ˜ํ–‰ํ•  ๋•Œ ์ฐธ์กฐ ์‘๋‹ต์— ๋Œ€ํ•œ ์ฒ˜๋ฆฌ๊ฐ€ ๋ฏธํกํ•˜์—ฌ ์„œ๋น„์Šค ๊ฑฐ๋ถ€๋ฅผ ์œ ๋ฐœํ•˜๋Š” ์ทจ์•ฝ์ (CVE-2020-8616) [1] o ๋ฉ”์‹œ์ง€์˜ ์œ ํšจ์„ฑ์„ ๊ฒ€์ฆํ•˜๋Š” BIND ์ฝ”๋“œ์—์„œ ํŠน์ • ๋ฉ”์‹œ์ง€์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๋ฐœ์ƒํ•˜๋Š” ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ์ทจ์•ฝ์ (CVE-2020-8617) [2] โ–ก ์˜ํ–ฅ๋ฐ›๋Š” ์†Œํ”„ํŠธ์›จ์–ด o BIND - 9.0.0 ~ 9.11.18 ๋ฒ„์ „ - 9.12.0 ~ 9.12.4-P2 ๋ฒ„์ „ - 9... 2020. 5. 26.
[Linux] ์ผ๋ฐ˜ ๊ณ„์ •์—์„œ SUDO ์‚ฌ์šฉ ๋ฐ SUDOERS ์„ค์ • ํ•˜๊ธฐ ์šฐ์„  ์„ค๋ช…์˜ ๊ธฐ๋ฐ˜์€ CentOS 8 ๊ธฐ์ค€์œผ๋กœ ์ง„ํ–‰ํ•˜์˜€๋‹ค. CentOS์™€ ๊ฐ™์ด Linux์—๋Š” ๊ด€๋ฆฌ์ž ๊ณ„์ •๊ณผ ์ผ๋ฐ˜ ๊ณ„์ •์ด ๋‚˜๋ˆ ์ ธ ์šด์˜์ด ๋œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ผ๋ฐ˜ ๊ณ„์ •์œผ๋กœ ์‚ฌ์šฉํ•˜๋‹ค ๋ณด๋ฉด ์ผ๋ฐ˜ ๊ณ„์ •์—์„œ Root ๊ถŒํ•œ์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. ์ด๋•Œ sudo ๋ผ๋Š” ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด์„œ ์ž„์‹œ์ ์œผ๋กœ Root ๊ถŒํ•œ์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ด€๋ฆฌ์ž๊ฐ€ ํ•ด๋‹น ์ผ๋ฐ˜ ๊ณ„์ •์— sudo ์‚ฌ์šฉ ๊ถŒํ•œ์„ ์ฃผ์ง€ ์•Š๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉํ•  ์ˆ˜๊ฐ€ ์—†๋‹ค. ๋˜ํ•œ, ์•„๋ž˜์™€ ๊ฐ™์ด "xxx์€(๋Š”) sudoers ์„ค์ • ํŒŒ์ผ์— ์—†์Šต๋‹ˆ๋‹ค. ์ด ์‹œ๋„๋ฅผ ๋ณด๊ณ ํ•ฉ๋‹ˆ๋‹ค."๋ผ๋Š” ์˜ค๋ฅ˜ ๋ฉ”์„ธ์ง€๋„ ์ถœ๋ ฅ ๋œ๋‹ค. $ sudo -i [sudo] xxx์˜ ์•”ํ˜ธ: xxx์€(๋Š”) sudoers ์„ค์ • ํŒŒ์ผ์— ์—†์Šต๋‹ˆ๋‹ค. ์ด ์‹œ๋„๋ฅผ ๋ณด๊ณ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿผ ์‚ฌ์šฉ์„ ์œ„ํ•ด์„œ๋Š” ๊ด€๋ฆฌ์ž๊ฐ€ sudoers ํŒŒ์ผ ์„ค์ •์ด ํ•„์š” ํ•˜.. 2020. 5. 17.
[Info] ์œ ๋ช… ๋ผ์šฐํ„ฐ / ๊ณต์œ ๊ธฐ ๊ธฐ๋ณธ ์•„์ด๋”” / ํŒจ์Šค์›Œ๋“œ ์ •๋ณด(Famous Router / Hub Default ID/Password Information) ์ธํ„ฐ๋„ท์„ ๋Œ์•„๋‹ค๋‹ˆ๋‹ค ๋ณด๋ฉด ์œ ๋ช… ๋ผ์šฐํ„ฐ(Router) / ๊ณต์œ ๊ธฐ ๊ธฐ๋ณธ ์•„์ด๋””/ํŒจ์Šค์›Œ๋“œ(ID/Password) ์ •๋ณด๊ฐ€ ๋…ธ์ถœ๋˜์–ด ์žˆ๋‹ค. ์ด๋Ÿฌ๋‹ค ๋ณด๋‹ˆ ๊ฐœ์ธ / ๊ธฐ์—…, ๊ณต๊ณต๊ธฐ๊ด€๋“ฑ์—์„œ ๋ผ์šฐํ„ฐ(Router) / ๊ณต์œ ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ณณ์—์„œ๋Š” ๋‹น์—ฐํžˆ ๊ธฐ๋ณธ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์•„์ด๋””/ํŒจ์Šค์›Œ๋“œ(ID/Password)๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์•„์•ผ ํ•œ๋‹ค. ๋งŒ์•ฝ ๊ธฐ๋ณธ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์•„์ด๋””/ํŒจ์Šค์›Œ๋“œ(ID/Password)๋ฅผ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ์ธํ„ฐ๋„ท๋งŒ ๋Œ์•„๋‹ค๋‹ˆ๋ฉด ์ˆ˜์ง‘ํ•  ์ˆ˜ ์žˆ๋Š” ์ •๋ณด๋ฅผ ํ†ตํ•ด์„œ ๊ด€๋ฆฌ์ž ํ™”๋ฉด ๋ฐ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ๋„˜๊ฒจ์ค„ ์ˆ˜ ์žˆ๋‹ค. ๋ฐ˜๋“œ์‹œ ๊ธฐ๋ณธ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์•„์ด๋””/ํŒจ์Šค์›Œ๋“œ(ID/Password)๋Š” ์‚ฌ์šฉํ•˜์ง€ ๋ง๋„๋ก ํ•˜์ž. ์ถ”๊ฐ€์ ์œผ๋กœ ์ •๋ณด๋“ค์ด ์ˆ˜์ง‘ ๋˜๋ฉด ๊ณ„์†์ ์œผ๋กœ ์ถ”๊ฐ€ํ•˜๋„๋ก ํ•˜๊ฒ ๋‹ค. ์—…์ฒด๋ช… ์•„์ด๋””/ํŒจ์Šค์›Œ๋“œ(ID/Password) 4ipnet Admin/A.. 2020. 5. 12.
[Info] ์นด์นด์˜คํ†ก/์นดํ†ก(KakaoTalk) ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ํŒŒ์ผ ํ™•์žฅ์ž ์ •๋ณด ์นด์นด์˜คํ†ก/์นดํ†ก(KakaoTalk)์„ ์‚ฌ์šฉํ•˜๋‹ค ๋ณด๋ฉด PC ํ˜น์€ ํœด๋Œ€๊ธฐ๊ธฐ๋ฅผ ํ†ตํ•ด์„œ ํŒŒ์ผ์„ ์ฃผ๊ณ ๋ฐ›๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ฐ„ํ˜น ํŒŒ์ผ์ด ์ „์†ก๋˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. ๋‹น์—ฐํžˆ ๋ฌธ์ œ ๋˜๋Š” ํŒŒ์ผ ํ˜น์€ ํ™•์žฅ์ž๋ฅผ ์ œ์–ดํ•˜๊ณ  ์žˆ๊ฒ ์ง€๋งŒ, ์–ด๋–ค ํŒŒ์ผ๋“ค์„ ์ฃผ๊ณ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š”์ง€ ์•Œ์•„๋ณด์ž. 1. ํŒŒ์ผ ํ™•์žฅ์ž ์ •๋ณด ์นด์นด์˜คํ†ก PC์—์„œ ๋ฌธ์„œ, ๋™์˜์ƒ, ์˜ค๋””์˜ค, ์ด๋ฏธ์ง€, ์••์ถ• ํŒŒ์ผ ๋“ฑ ๊ฐœ๋‹น ์ตœ๋Œ€ 300MB๊นŒ์ง€ ์ „์†ก์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ฃผ๊ณ ๋ฐ›์€ ํŒŒ์ผ๋“ค์€ PC์™€ ๋ชจ๋ฐ”์ผ์—์„œ ๋ชจ๋‘ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. [์ด๋ฏธ์ง€] - jpg, jpeg, gif, bmp, png, tif, tiff, tga, psd, ai [๋™์˜์ƒ] - mp4, m4v, avi, asf, wmv, mkv, ts, mpg, mpeg, mov, flv, ogv [์Œ์„ฑ] - mp3, wav, fl.. 2020. 5. 12.
[Linux] Python(ํŒŒ์ด์ฌ) pyenv virtualenv Install(์„ค์น˜ํ•˜๊ธฐ) Linux์— Pyenv์„ ์„ค์น˜ํ•ด์„œ ์‚ฌ์šฉํ•ด ๋ณด์ž. ๊ธฐ๋ณธ ํ™˜๊ฒฝ : CentOS 7.x Git 1.8 1.pyenv ์„ค์น˜๋ฅผ ์œ„ํ•œ ์‚ฌ์ „ ์ค€๋น„ $ yum install -y bzip2 bzip2-develcurl gcc gcc-c++ git libffi-devel make openssl-devel readline-devel sqlite sqlite-devel xz xz-devel zlib-devel 2. pyenv-installer ์„ค์น˜ $ curl -L https://raw.githubusercontent.com/pyenv/pyenv-installer/master/bin/pyenv-installer | bash ํ™˜๊ฒฝ ๋ณ€์ˆ˜ ์„ค์ • $ echo 'export PYENV_ROOT="$HOME/.pyenv"' >> ~/.. 2020. 5. 11.
[Info] MacBook(๋งฅ๋ถ)์—์„œ Chromecast(ํฌ๋กฌ์บ์ŠคํŠธ) ์—ฐ๋™ ํ•˜๊ธฐ ๋‹ค๋ฅธ ์šฉ๋„๋กœ Chromecast(ํฌ๋กฌ์บ์ŠคํŠธ)๋ฅผ ๊ตฌ๋งคํ•˜์—ฌ Android(์•ˆ๋“œ๋กœ์ด๋“œ) ๋ฐ iPhone(์•„์ดํฐ) ๊ธฐ๊ธฐ์„ ์ด์šฉํ•˜์—ฌ ๋งŽ์€ ๋ถ€๋ถ„์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋˜ ๋„์ค‘, iPhone(์•„์ดํฐ)์—์„œ๋„ ๋˜๋Š”๊ฑธ ๋ณด๊ณ  MacBook(๋งฅ๋ถ)์˜ ํ™”๋ฉด๋„ Apple TV(์• ํ”Œ TV)์™€ ๊ฐ™์ด Chromecast(ํฌ๋กฌ์บ์ŠคํŠธ)๋ฅผ ์ด์šฉํ•˜์—ฌ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์ง€ ์•Š์„๊นŒ ํ•˜๋Š” ์˜๋ฌธ์ด ์ƒ๊ฒผ๋‹ค. ์ œ์ผ ์ข‹์€ ๋ฐฉ๋ฒ•์€ Apple TV(์• ํ”Œ TV) ํ˜น์€ USB-C to HDMI Cable์„ ํ†ตํ•ด์„œ ์—ฐ๊ฒฐ์„ ํ•  ์ˆ˜ ์žˆ์œผ๋‚˜, ์œ ์„ ์€ Cable(์ผ€์ด๋ธ”)์ด ๊ณ„์† ๊ฑฐ์Šฌ๋ฆฌ๊ณ , ๋ฌด์„ ์œผ๋กœ Apple TV(์• ํ”Œ TV)๋ฅผ ๋‹ค์‹œ ๊ตฌ๋งค๋ฅผ ํ•ด์•ผํ•˜๋Š” ์ƒํ™ฉ์ด๋ผ ํ˜น์‹œ ๋ชฐ๋ผ Chromecast(ํฌ๋กฌ์บ์ŠคํŠธ) ํŽ˜์ด์ง€๋ฅผ ๋ฐฉ๋ฌธํ•ด ๋ณด์•˜๋‹ค. ๋ฐฉ๋ฌธํ•˜์—ฌ ๋‚ด์šฉ๋“ค์„ ์‚ดํŽด๋ณด๋‹ค ๋ณด๋‹ˆ ์˜ˆ์ƒํ•˜์ง€ ๋ชปํ–ˆ๋˜ ๋‚ด์šฉ์ด ์ ํ˜€.. 2020. 5. 10.
[Info] iOS Universal Links(์œ ๋‹ˆ๋ฒ„์…œ ๋งํฌ) ์„ค์ • On / Off ํ•˜๊ธฐ(a.k.a ํด๋ž˜์ŠคํŒ… watchpopup ์˜ค๋ฅ˜ ํ•ด๊ฒฐ) Universal Links(์œ ๋‹ˆ๋ฒ„์…œ ๋งํฌ)๋ž€ iOS9 ์ด์ƒ ๋ฒ„์ „์—์„œ Web(์›น), App(์•ฑ)๋‚ด์—์„œ ํŠน์ • Link(๋งํฌ)๋ฅผ ํด๋ฆญํ•˜์˜€์„๋•Œ, Safari browser(์‚ฌํŒŒ๋ฆฌ ๋ธŒ๋ผ์šฐ์ €)๊ฐ€ ์•„๋‹Œ ๋ฐ”๋กœ ์„ค์น˜๋œ App(์•ฑ)์œผ๋กœ ์—ฐ๊ฒฐ ํ•˜๋Š” ๊ธฐ์ˆ ์ด๋‹ค. ๋งŒ์•ฝ ํ•ด๋‹น Link(๋งํฌ)์™€ ์—ฐ๊ฒฐ๋œ App(์•ฑ)์ด ์กด์žฌํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๋Š” Safari browser(์‚ฌํŒŒ๋ฆฌ ๋ธŒ๋ผ์šฐ์ €)๋กœ ์—ฐ๊ฒฐํ•˜์—ฌ ์‚ฌ์šฉ๋œ๋‹ค. ํ•ด๋‹น ๊ธฐ์ˆ ์„ ์‰ฝ๊ฒŒ ์„ค๋ช…ํ•˜๋ฉด ์•„์ดํฐ(iPhone)์— Youtube App(์œ ํŠœ๋ธŒ ์•ฑ)์ด ์„ค์น˜๋˜์–ด ์žˆ๊ณ , Web(์›น), App(์•ฑ)๋‚ด์— ์กด์žฌํ•˜๋Š” ์œ ํŠœ๋ธŒ Link(๋งํฌ)๋ฅผ ํด๋ฆญ์‹œ Safari browser(์‚ฌํŒŒ๋ฆฌ ๋ธŒ๋ผ์šฐ์ €)์ด ์•„๋‹Œ Youtube App(์œ ํŠœ๋ธŒ ์•ฑ)์ด ์‹คํ–‰๋˜๊ฒŒ ๋œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ด๋Ÿฐํ•œ ๊ธฐ์ˆ ์€ ์ž˜ ์‚ฌ์šฉ๋˜๊ณ  ์žˆ์ง€๋งŒ, ๊ฐ„ํ˜น App(.. 2020. 5. 9.
[KISA] Wi-Fi ์นฉ์…‹ ์ทจ์•ฝ์  ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o Broadcom, Cypress็คพ์˜ WiFi ์นฉ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋ฐœํ‘œ o ์˜ํ–ฅ๋ฐ›๋Š” ๋ฒ„์ „์„ ์‚ฌ์šฉ์ค‘์ธ ์ด์šฉ์ž๋Š” ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋“ฑ์˜ ์šฐ๋ ค๊ฐ€ ์žˆ์œผ๋ฏ€๋กœ ํ•ด๊ฒฐ ๋ฐฉ์•ˆ์— ๋”ฐ๋ผ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ์„ค๋ช… o Broadcom, Cypress ็คพ์˜ ํŠน์ • WiFi ์นฉ์…‹์—์„œ Wi-Fi ๋ฌด์„  ๊ตฌ๊ฐ„์—์„œ ์ „์†ก๋˜๋Š” ์ผ๋ถ€ ํŠธ๋ž˜ํ”ฝ์ด ๋…ธ์ถœ๋  ์ˆ˜ ์žˆ๋Š” ์ •๋ณด๋…ธ์ถœ ์ทจ์•ฝ์ (CVE-2019-15126) [1] โ–ก ์˜ํ–ฅ๋ฐ›๋Š” ์ œํ’ˆ o Broadcom, Cypress ็คพ์˜ ์ทจ์•ฝํ•œ ์นฉ์…‹์ด ํƒ‘์žฌ๋œ ์Šค๋งˆํŠธํฐ, IoT, ๊ณต์œ ๊ธฐ ๋“ฑ ๋ชจ๋“  ๊ธฐ๊ธฐ o ์ทจ์•ฝํ•œ ์นฉ์…‹ : Bcm43012, Bcm43013, Bcm4356, Bcm4375, Bcm4389, Bcm43752 โ–ก ํ•ด๊ฒฐ ๋ฐฉ์•ˆ o ์ œ์กฐ์‚ฌ์˜ ์—…๋ฐ์ดํŠธ ํ™ˆํŽ˜์ด์ง€๋ฅผ ์ฐธ๊ณ ํ•˜์—ฌ.. 2020. 5. 8.
[KISA] ์‚ผ์„ฑ์ „์ž ๋ชจ๋ฐ”์ผ ๊ธฐ๊ธฐ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๊ถŒ๊ณ  โ–ก ๊ฐœ์š” o ์‚ผ์„ฑ์ „์ž๋Š” ์ž์‚ฌ ๋ชจ๋ฐ”์ผ ๊ธฐ๊ธฐ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•œ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ ๋ฐœํ‘œ [1] โ–ก ์„ค๋ช… o ์œ„ํ—˜๋„ : ์‹ฌ๊ฐ(Critical) - ํ€„์ปด ์นฉ์—์„œ ๋ฐฐ์—ด์˜ ์ธ๋ฑ์Šค ๊ฐ’์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๊ฒฝ๊ณ„๊ฐ’์„ ๋ฒ—์–ด๋‚˜ ์“ฐ๊ธฐ๊ฐ€ ๊ฐ€๋Šฅํ•œ ์ทจ์•ฝ์ (CVE-2019-10609) ๋“ฑ 11๊ฐœ o ์œ„ํ—˜๋„ : ๋†’์Œ(High) - ํ€„์ปด ์นฉ์—์„œ ๋ ˆ์ด์Šค ์ปจ๋””์…˜์œผ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ ํ•ด์ œ ์ดํ›„ ์žฌ์‚ฌ์šฉ(Use-After-Free) ์ทจ์•ฝ์ (CVE-2019-14070) ๋“ฑ 39๊ฐœ o ์œ„ํ—˜๋„ : ์ค‘๊ฐ„(Moderate) - NFC ์ปดํฌ๋„ŒํŠธ์—์„œ ์ž…๋ ฅ๊ฐ’ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ๊ฒฝ๊ณ„๊ฐ’์„ ๋ฒ—์–ด๋‚œ ์“ฐ๊ธฐ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•˜๋Š” ๊ถŒํ•œ ์ƒ์Šน ์ทจ์•ฝ์ (CVE-2020-0050) ๋“ฑ 19๊ฐœ o ์œ„ํ—˜๋„ : ๋‚ฎ์Œ(Low) - ํด๋ฆฝ๋ณด๋“œ์— ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ๊ฐ€ USSD๋ฅผ ํ†ตํ•ด ๋…ธ์ถœ.. 2020. 5. 8.
728x90
300x250

loading