Home
|
Data Center
|
Contact US
|
Login
Á¦¸ñ
¾ÈÀüÇÑ ¾ÆÀÌÆù ÀÌ¿ëÀ» À§ÇÑ ÃֽŠ¾÷µ¥ÀÌÆ® ±Ç°í
ÀÛ¼ºÀÏ
2010-06-28 10:59:06
¾ÈÀüÇÑ ¾ÆÀÌÆù ÀÌ¿ëÀ» À§ÇÑ ÃֽŠ¾÷µ¥ÀÌÆ® ±Ç°í
¡à °³¿ä
o ÃÖ±Ù ¾ÖÇÃÞä¿¡¼ ¾ÆÀÌÆù(iPhone) ¿î¿µÃ¼Á¦ ÃֽŠ¹öÀüÀÎ iOS 4À» °ø°³ [1]
o iOS 4´Â ¾ÆÀÌÆù(iPhone) ¹× ¾ÆÀÌÆÌÅÍÄ¡(iPod Touch)¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ Æ÷ÇÔÇÔ [1]
- iOS 4´Â ÀÌ¿ëÀÚ ¾îÇø®ÄÉÀ̼ÇÀ» ºñÁ¤»óÀûÀ¸·Î Á¾·á½ÃÅ°°Å³ª ÀÌ¿ëÀÚ ´Ü¸»±â¿¡ ¾Ç¼ºÄڵ带 °¨¿°
½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®¸¦ Æ÷ÇÔ
o ÀÌ¿¡ ±¹³» ¾ÆÀÌÆù ¹× ¾ÆÀÌÆÌÅÍÄ¡ ÀÌ¿ëÀÚµéÀº ¼ÒÇÁÆ®¿þ¾î ¾÷µ¥ÀÌÆ®¸¦ ±Ç°íÇÔ [1]
¡à ¼³¸í
o ÃÖ±Ù ¾ÖÇÃÞä¿¡¼ Ãë¾àÁ¡ 64°³¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ Æ÷ÇÔÇÏ´Â iPhone iOS 4¸¦ °ø°³[1]
- Application Sandbox (CVE-2010-1751) : Application Sandbox°¡ ¾îÇø®ÄÉÀ̼ÇÀÌ ÀÌ¿ëÀÚÀÇ
»çÁøÀ» ó¸®ÇÔ¿¡ ÀÖ¾î ¹æ¹®Çß´ø À§Ä¡ Á¤º¸¸¦ ±ÇÇÑÀÌ ¾ø¾îµµ Á¢±ÙÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [2]
- CFNetwork (CVE-2010-1752) : CFNetworkÀÇ URLÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ½ºÅà ¿À¹öÇ÷ο찡
¹ß»ýÇÏ¿© ¾îÇø®ÄÉÀ̼ÇÀÌ Á¾·áµÇ°Å³ª ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ [3]
- ImageIO (CVE-2010-0041, CVE-2010-0042) : ÇØÄ¿¿¡ ÀÇÇØ ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥»çÀÌÆ®¸¦
¹æ¹® ÇÒ °æ¿ì safari À¥ºê¶ó¿ìÀúÀÇ ¸Þ¸ð¸® ¿µ¿ªÀÇ µ¥ÀÌÅ͸¦ ƯÁ¤ À¥»çÀÌÆ®¿¡ Àü¼ÛÇÒ ¼ö ÀÖ´Â
Ãë¾àÁ¡ [4],[5]
- ImageIO (CVE-2010-0043, CVE-2010-1753) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ TIFF ¹× JPEG À̹ÌÁö¸¦
ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¾îÇø®ÄÉÀ̼ÇÀÌ Á¾·áÇϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [6],[7]
- LibSystem (CVE-2009-0689) :¡¡½Å·ÚµÇÁö ¾Ê´Â µ¥ÀÌÅ͸¦ Çüº¯È¯ÇÏ´Â °úÁ¤¿¡¼ ÇÁ·Î±×·¥ÀÌ
ºñÁ¤»óÀûÀ¸·Î Á¾·áµÇ°Å³ª ÀÓÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [8]
- libxml (CVE-2009-2414, CVE-2009-2416) : ÇØÄ¿¿¡ ÀÇÇØ ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ XMLÀ» ó¸®ÇÏ´Â
°úÁ¤¿¡¼ ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»óÀûÀ¸·Î Á¾·áµÇ´Â Ãë¾àÁ¡ [9],[10]
- Passcode Lock (CVE-2010-1754) : MobileMe¸¦ ÀÌ¿ëÇÏ¿© ¿ø°Ý Àá±ÝÀ» ÇÒ °æ¿ì Á¤»óÀûÀ¸·Î
¾ÆÀÌÆùÀÌ Àá±Ý(Passcode lock: Æнº¿öµå Àá±Ý)ÀÌ µÇÁö ¾ÊÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡ [11]
- Passcode Lock (CVE-2010-1775) : ¹°¸®ÀûÀ¸·Î ´Ü¸»±â(¾ÆÀÌÆù)¿¡ Á¢±Ù °¡´ÉÇÑ °ø°ÝÀÚ°¡
ÀÌ¿ëÀÚÀÇ µ¥ÀÌÅÍ¿¡ Á¢±Ù°¡´ÉÇÑ Ãë¾àÁ¡ÀÔ´Ï´Ù. [12]
- Safari (CVE-2010-1754) : ¼ö½Å Cookie ¼³Á¤ÀÌ Á¤»óÀûÀ¸·Î Àû¿ëµÇÁö ¾Ê´Â Ãë¾àÁ¡ [13]
- Safari (CVE-2010-1384) : Ư¼öÇÏ°Ô Á¶ÀÛµÈ URLÀÌ ³µ¶ÈµÇ¾î Çǽ̰ø°Ý¿¡ ÀÌ¿ëµÉ ¼ö ÀÖ´Â
Ãë¾àÁ¡[14]
- Safari (CVE-2009-1723) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥»çÀÌÆ®¸¦ ¹æ¹®ÇÒ °æ¿ì ÀÎÁõ¼ °æ°í°¡ Ç¥½ÃµÇ´õ
¶óµµ À¥»çÀÌÆ®¿¡ Ç¥½ÃµÇ´Â URL À» Á¶ÀÛÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [15]
- Settings (CVE-2010-1756) : Settings ¾îÇø®ÄÉÀ̼ÇÀÇ ¿À·ù·Î ´Ù¸¥ ¹«¼± ³×Æ®¿öÅ©¿¡ Á¢¼ÓÇÒ ¼ö
ÀÖ´Â Ãë¾àÁ¡ [16]
- WebKit (CVE-2009-2195) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [17]
- WebKit (CVE-2009-2816) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ´Ù¸¥ À¥»çÀÌÆ®¿¡ ºñÁ¤»óÀûÀÎ
ÇൿÀ» ÃëÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [18]
- WebKit (CVE-2010-0544) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã Cross site scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [19]
- WebKit (CVE-2010-1395) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã Cross site scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [20]
- WebKit (CVE-2010-0051) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¹Î°¨ÇÑ Á¤º¸¸¦ ³ëÃâ½ÃÅ°´Â
Ãë¾àÁ¡ [21]
¡¡¡¡- WebKit (CVE-2010-1390) : UTF-7 ÀÎÄÚµùµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã Cross site scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [22]
¡¡¡¡- WebKit (CVE-2010-0047) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [23]
¡¡¡¡- WebKit (CVE-2010-0053) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [24]
¡¡¡¡- WebKit (CVE-2010-0047) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [25]
- WebKit (CVE-2010-1406) : HTTP »çÀÌÆ®·Î ¿¬°á(redirect)ÇÏ´Â HTTPS »çÀÌÆ®¿¡ ¹æ¹®ÇÒ °æ¿ì
Á¤º¸¸¦ ³ëÃâ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡ [26]
¡¡¡¡- WebKit (CVE-2010-0048) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [27]
- WebKit (CVE-2010-0046) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [28]¡¡
- WebKit (CVE-2010-0052) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [29]
- WebKit (CVE-2010-1397) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [30]
- WebKit (CVE-2010-0049) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [31]
- WebKit (CVE-2010-1393) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã Á¤º¸°¡ ³ëÃâµÇ´Â Ãë¾àÁ¡ [32]
- WebKit (CVE-2010-0054) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [33]
- WebKit (CVE-2010-1119) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [34]
- WebKit (CVE-2010-1387) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [35]
- WebKit (CVE-2010-1400) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [36]
- WebKit (CVE-2010-1409) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã IRC ¼¹ö·Î ƯÁ¤ µ¥ÀÌÅ͸¦
Àü¼ÛÇÏ´Â Ãë¾àÁ¡ [37]
- WebKit (CVE-2010-1398) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [38]
- WebKit (CVE-2010-1402) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [39]
- WebKit (CVE-2010-1394) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã cross-site-scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [40]
- WebKit (CVE-2010-1399) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [41]
- WebKit (CVE-2010-1396) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [42]
- WebKit (CVE-2010-1401) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [43]
- WebKit (CVE-2010-1403) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [44]
- WebKit (CVE-2010-1404) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [45]
- WebKit (CVE-2010-1410) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [46]
- WebKit (CVE-2010-1391) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ÀÌ¿ëÀÚ°¡ ¾²±â±ÇÇÑÀ» Áö´Ñ
À§Ä¡¿¡ ÀÓÀÇÀÇ ÆÄÀÏÀ» »ý¼ºÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [47]
- WebKit (CVE-2010-1408) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ÀÓÀÇÀÇ TCP Æ÷Æ®·Î µ¥ÀÌÅ͸¦
Àü¼ÛÇÒ ¼ö ÀÖ´Â Ãë¾à [48]
- WebKit (CVE-2010-1392) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [49]
- WebKit (CVE-2010-1405) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [50]
- WebKit (CVE-2010-1407) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã Á¤º¸¸¦ ³ëÃâ½ÃÅ°´Â
Ãë¾àÁ¡ [51]
- WebKit (CVE-2010-1757) : iframeÀ» Æ÷ÇÔÇÏ´Â À¥»çÀÌÆ®°¡ »ç¿ëÀÚ ÀÎÅÍÆäÀ̽º spoofingÀ» ¹ß»ý
ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ [52]
- WebKit (CVE-2010-1413) : ÀÌ¿ëÀÚÀÇ NTLM Á¤º¸°¡ MITM(Man In the midddle) °ø°ÝÀÚ¿¡°Ô
³ëÃâ µÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ [53]
- WebKit (CVE-2010-1389) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [54]
- WebKit (CVE-2010-1774, CVE-2010-1769) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®
ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·áÇϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [55],[56]
- WebKit (CVE-2010-1762) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã cross-site-scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [57]
- WebKit (CVE-2010-1759) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [58]
- WebKit (CVE-2010-1758) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [59]
- WebKit (CVE-2010-1415) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [60]
- WebKit (CVE-2010-1416) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [61]
- WebKit (CVE-2010-1418) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã cross-site-scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [62]
- WebKit (CVE-2010-1414) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [63]
- WebKit (CVE-2010-1417) : ÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã ¾îÇø®ÄÉÀ̼ÇÀÌ ºñÁ¤»ó Á¾·á
Çϰųª ÀÓÀÇ Äڵ带 ½ÇÇàÇÏ´Â Ãë¾àÁ¡ [64]
- WebKit (CVE-2010-0544) : ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ Á¢¼Ó½Ã cross-site-scripting °ø°ÝÀÌ
°¡´ÉÇÑ Ãë¾àÁ¡ [65]
¡à ¾÷µ¥ÀÌÆ® ¹æ¹ý
¨ç PC¿¡¼ ¾ÆÀÌƪÁ ½ÇÇàÇÏ°í iPhoneÀ» PC¿Í ¿¬°á
¨è ¡°¾÷µ¥ÀÌÆ® È®ÀΡ± ¹öÆ°À» Ŭ¸¯ÇÏ¿© ¼ÒÇÁÆ®¿þ¾î ¾÷µ¥ÀÌÆ®
¡à ¿ë¾î Á¤¸®
o WebKit : Apple Safari ¹× Google Å©·Ò ºê¶ó¿ìÀú¸¦ Æ÷ÇÔÇÑ ´Ù¼öÀÇ ¾îÇø®ÄÉÀ̼ǿ¡¼ »ç¿ëµÇ´Â
ºê¶ó¿ìÀú ÇÁ·¹ÀÓ¿öÅ©
o Application Sandbox : ½ÇÇàÁßÀÎ ¾îÇø®ÄÉÀ̼ÇÀÌ ¼·Î ¿µÇâÀ» ÁÖÁö ¸øÇϵµ·Ï ºÐ¸® µ¶¸³½ÃÅ°´Â
º¸¾È ¸ÞÄ¿´ÏÁò
¡à ±âŸ ¹®ÀÇ»çÇ×
o JailbreakµÈ iPhoneµµ ¾÷µ¥ÀÌÆ®°¡ °¡´ÉÇÑ°¡¿ä?
- ¾÷µ¥ÀÌÆ®°¡ °¡´ÉÇÕ´Ï´Ù. ¾ÆÀÌƪÁ ÅëÇØ ¾÷µ¥ÀÌÆ®¸¦ ÇÏ½Ã±æ ¹Ù¶ø´Ï´Ù.
¡Ø ´Ü, º» ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÒ °æ¿ì Jailbreak°¡ Àû¿ëµÇÁö ¾ÊÀº »óÅ·Πµ¹¾Æ°©´Ï´Ù.
o iOS 4 ¾÷±×·¹À̵å ÈÄ ÀϺΠ¾îÇø®ÄÉÀ̼ÇÀÌ ÀÛµ¿µÇÁö ¾Ê´Â ¹®Á¦°¡ ÀÖ½À´Ï´Ù.
- ÀϺΠÀºÇà±Ç ¾îÇø®ÄÉÀ̼ÇÁß¿¡ ½ÇÇ൵Áß ºñÁ¤»óÀûÀ¸·Î Á¾·áµÇ´Â ¹®Á¦°¡ ÀÖ½À´Ï´Ù.
ÇöÀç ÇØ´ç °³¹ß¾÷ü¿¡¼ ¹öÀü ¾÷±×·¹À̵åÁßÀÌ´Ï iOS 4¾÷±×·¹À̵å ÈÄ¿¡ ÇØ´ç ¾îÇø®ÄÉÀ̼ǵµ
¹Ýµå½Ã ¾÷µ¥ÀÌÆ® ÇϽñ⠹ٶø´Ï´Ù.
¡à Âü°í»çÀÌÆ®
[1]
http://support.apple.com/kb/HT4225
[2]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1751
[3]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1752
[4]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0041
[5]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0042
[6]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0043
[7]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1753
[8]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0689
[9]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414
[10]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2416
[11]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1754
[12]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1775
[13]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1754
[14]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1384
[15]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1723
[16]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1756
[17]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2195
[18]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2816
[19]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0544
[20]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1395
[21]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0051
[22]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1390
[23]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0047
[24]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0053
[25]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0047
[26]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1406
[27]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0048
[28]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0046
[29]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0052
[30]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1397
[31]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0049
[32]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1393
[33]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0054
[34]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1119
[35]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1387
[36]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1400
[37]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1409
[38]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1398
[39]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1402
[40]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1394
[41]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1399
[42]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1396
[43]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1401
[44]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1403
[45]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1404
[46]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1410
[47]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1391
[48]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1408
[49]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1392
[50]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1405
[51]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1407
[52]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1757
[53]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1413
[54]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1389
[55]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1774
[56]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1769
[57]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1762
[58]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1759
[59]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1758
[60]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1415
[61]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1416
[62]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1418
[63]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1414
[64]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1417
[65]
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0544
Adobe Reader/Acrobat ´ÙÁß Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í
[³×ÀÓ¼¹öº¯°æ]³Ø½ºÆ®¶óÀÎ 1Â÷ ³×ÀÓ¼¹ö º¯°æ ¾È³»