¡à °³¿ä o Java °³¹ß ¹× ½ÇÇàȯ°æÀÎ JDK/JRE 6 Update 10 ÀÌÈÄ ¹öÀüÀÇ ÀÚ¹Ù ¹èÆ÷ µµ±¸ (Java Deployment Toolkit) Ç÷¯±×Àΰú ActiveX ÄÁÆ®·Ñ¿¡¼ ¸Å°³º¯¼ö·Î Àü´ÞµÇ´Â ÀԷ°ª °ËÁõ ¿À·ù ¹× Update 18 ÀÌÈÄ ¹öÀüÀÇ ÀÚ¹Ù Ç÷¯±×ÀÎÀÇ ¿À·ù·Î ÀÎÇØ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ÀÌ ¹ß»ý [1, 2, 4] o °ø°ÝÀڴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö·Î »ç¿ëÀÚ¸¦ À¯µµÇÏ¿©, ÇØ´ç ½Ã½ºÅÛ¿¡¼ ¾ÇÀÇÀûÀÎ Java ÆÄÀÏ(JAR)À» ½ÇÇàÇÒ ¼ö ÀÖÀ½ [2] o ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¾Ç¼ºÄڵ带 ÀüÆÄÇÏ´Â »ç·Ê[6]°¡ ¹ß°ßµÇ¾î ÁÖÀÇ°¡ ¿ä±¸µÊ o °ü·ÃÃë¾àÁ¡ : - Java Deployment Toolkit Ãë¾àÁ¡ (CVE-2010-0886) - New Java Plug-in Ãë¾àÁ¡ (CVE-2010-0887)
¡à ÇØ´ç ½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î [4] - Java SE JDK/JRE 6 Update 10 ~ Update 19 - Java for Business JDK/JRE 6 Update 10 ~ Update 19 ¡Ø Windows, Solaris, Linux Ç÷§Æû¿¡ °ü°è¾øÀÌ 32ºñÆ® À¥ ºê¶ó¿ìÀú¿¡¼ µ¿ÀÛÇÏ´Â Java Á¦Ç°¿¡¼ ¿µÇâÀ» ¹ÞÀ½
¡à ÇØ°á ¹æ¾È o Java SE ¶Ç´Â Java for Business JDK/JRE 6 Update 20À» ¼³Ä¡ [3, 4] ¡Ø Java ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤±Ç°í: Á¦¾îÆÇ¡æJava¡æ¾÷µ¥ÀÌÆ®¡æ"ÀÚµ¿ ¾÷µ¥ÀÌÆ® È®ÀÎ" ¼³Á¤ [7]
¡à ¿ë¾î Á¤¸® o Java : Sun Microsystems(úÞ Oracle)¿¡¼ °³¹ßÇÑ Ç÷§Æû µ¶¸³ÀûÀÎ °´Ã¼ ÁöÇâ ÇÁ·Î±×·¡¹Ö ¾ð¾î·Î, ÇØ´ç ¾ð¾î ±â¹ÝÀÇ Á¦Ç°À» ÅëĪÇÏ´Â Àǹ̷εµ »ç¿ëµÊ o Java Deployment Toolkit : Java ÀÀ¿ë ÇÁ·Î±×·¥À» ½±°Ô ¹èÆ÷ÇÒ ¼ö ÀÖ´Â ±â´ÉÀ» Á¦°øÇÏ´Â Netscape ȣȯ Ç÷¯±×Àΰú ActiveX ÄÁÆ®·Ñ [5] o JDK(Java Development Kit) : Java ÀÀ¿ë ÇÁ·Î±×·¥À» °³¹ßÇϱâ À§ÇÑ µµ±¸ o JRE(Java Runtime Environment) : Java ¾ð¾î·Î °³¹ßµÈ ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ½ÇÇà Ç÷§Æû o JAR(Java ARchive) : Java ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¶óÀ̺귯¸®¸¦ ¹èÆ÷Çϱâ À§ÇØ »ç¿ëµÇ´Â ½ÇÇà °¡´ÉÇÑ ÆÄÀÏ Æ÷¸Ë
¡à ÂüÁ¶»çÀÌÆ® [1] http://lists.grok.org.uk/pipermail/full-disclosure/2010-April/074036.html [2] http://www.kb.cert.org/vuls/id/886582 [3] http://www.java.com/ko/ [4] http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html [5] http://java.sun.com/javase/6/6u10faq.jsp#DT [6] http://blogs.zdnet.com/security/?p=6161 [7] http://www.java.com/ko/download/help/java_update.xml
|
|
|