2010³â 10¿ù OracleÀÇ Oracle Critical Patch Update ±Ç°í
¡à °³¿ä ¤· Oracle Critical Patch Update (CPU)´Â Oracle»çÀÇ Á¦Ç°À» ´ë»óÀ¸·Î ´Ù¼öÀÇ º¸¾È ÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ´Â ÁÖ¿ä ¼ö´ÜÀÓ ¤· 2010³â 10¿ù 12ÀÏ(ÇöÁö½Ã°¢) Oracle CPU ¹ßÇ¥ ÀÌÈÄ, °ü·Ã °ø°ÝÄÚµåÀÇ ÃâÇöÀ¸·Î ÀÎÇÑ ÇÇÇØ°¡ ¿¹»óµÇ´Â ¹Ù Oracle Á¦Ç°ÀÇ ´ÙÁß Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ ±Ç°íÇÔ
¡à ¼³¸í ¤· 2010³â 10¿ù Oracle CPU¿¡¼´Â Oracle ÀÚ»ç Á¦Ç°ÀÇ º¸¾ÈÃë¾àÁ¡ 85°³¿¡ ´ëÇÑ ÆÐÄ¡¸¦ ¹ßÇ¥ÇÔ - ¿ø°Ý ¹× ·ÎÄà °ø°ÝÀ» ÅëÇÏ¿© Ãë¾àÇÑ ¼¹ö¸¦ °ø°ÝÇϴµ¥ ¾Ç¿ëµÉ °¡´É¼ºÀÌ ÀÖ´Â Ãë¾àÁ¡À» Æ÷ÇÔÇÏ¿© DBÀÇ °¡¿ë¼º ¹× ±â¹Ð¼º/¹«°á¼º¿¡ ¿µÇâÀ» ÁÙ ¼ö ÀÖ´Â Ãë¾àÁ¡ Á¸Àç
¡à ÇØ´ç ½Ã½ºÅÛ ¿î¿µÃ¼Á¦ ¤· Oracle Database 11g Release 2, version 11.2.0.1 ¤· Oracle Database 11g Release 1, version 11.1.0.7 ¤· Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4 ¤· Oracle Database 10g, Release 1, version 10.1.0.5 ¤· Oracle Fusion Middleware, 11gR1, versions 11.1.1.1.0, 11.1.1.2.0 ¤· Oracle Application Server, 10gR3, version 10.1.3.5.0 ¤· Oracle Application Server, 10gR2, version 10.1.2.3.0 ¤· Oracle BI Publisher, versions 10.1.3.3.2, 10.1.3.4.0, 10.1.3.4.1 ¤· Oracle Identity Management 10g, versions, 10.1.4.0.1, 10.1.4.3 ¤· Oracle E-Business Suite Release 12, versions 12.0.4, 12.0.5, 12.0.6, 12.1.1 and 12.1.2 ¤· Oracle E-Business Suite Release 11i, versions 11.5.10, 11.5.10.2 ¤· Agile PLM, version 9.3.0.0 ¤· Oracle Transportation Management, versions 5.5, 6.0, and 6.1 ¤· PeopleSoft Enterprise CRM, FMS, HCM and SCM (Supply Chain), versions 8.9, 9.0 and 9.1 ¤· PeopleSoft Enterprise EPM, Campus Solutions, versions 8.9, 9.0 and 9.1 ¤· PeopleSoft Enterprise PeopleTools, versions 8.49 and 8.50 ¤· Siebel Core, versions 7.7, 7.8, 8.0 and 8.1 ¤· Primavera P6 Enterprise Project Portfolio Management, Versions: 6.21.3.0, 7.0.1.0 ¤· Oracle Sun Product Suite ¤· Oracle VM, version 2.2.1 ¡Ø ¿µÇâ¹Þ´Â ½Ã½ºÅÛÀÇ »ó¼¼ Á¤º¸´Â Âü°í»çÀÌÆ®[1]¸¦ ÂüÁ¶
¡à ÇØ°á ¹æ¾È ¤· ÇØ°á¹æ¾ÈÀ¸·Î¼ "Oracle Critical Patch Update Advisory - October 2010" ¹®¼¸¦ °ËÅäÇÏ°í º¥´õ»ç ¹× À¯Áöº¸¼ö¾÷ü¿Í ÇùÀÇ/°ËÅä ÈÄ ÆÐÄ¡Àû¿ë ¿ä¸Á[1] ¤· °¢ »çÀÌÆ®ÀÇ »çÁ¤À¸·Î ÆÐÄ¡Àû¿ëÀÌ Áö¿¬µÉ °æ¿ì, - ºÒÇÊ¿äÇÑ °èÁ¤À» »èÁ¦ÇÏ°í µðÆúÆ® Æнº¿öµå º¯°æ[2] - µ¥ÀÌÅͺ£À̽º Á¢±Ù ÅëÁ¦¸¦ ±¸ÇöÇÏ¿© »ç¿ëÀÚ¿¡°Ô Çã°¡µÇ´Â ±ÇÇÑÀ» ÃÖ¼ÒÈÇÔÀ¸·Î½á, °ø°ÝÀ¸·Î ÀÎÇØ ¹ß»ýµÉ ¿µÇâÀ» Á¦ÇÑ - ¿µÇâÀ» ¹Þ´Â ¼ºñ½º¿¡ ´ëÇؼ´Â ½Å·ÚµÈ È£½ºÆ® ¹× ³×Æ®¿öÅ©µé¸¸ ¾×¼¼½ºÇÒ ¼ö ÀÖµµ·Ï Á¦ÇÑ - µ¥ÀÌÅͺ£À̽º º¸¾ÈÁ¦Ç° È°¿ë
¡à Âü°í»çÀÌÆ® [1] http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html [2] http://www.krcert.or.kr/cyberSecureManual/cyber.jsp "¹Î°£»çÀ̹ö¾ÈÀü¸Å´º¾ó ±â¾÷ Á¤º¸º¸È£´ã´çÀÚ¿ë", 228p ~ 236p, 2006,
¡à Âü°í 1. F.A.Q ¤·¹æȺ®À» »ç¿ëÇÏ¿© ¿ÜºÎ¿¡¼ ³»ºÎ Database·ÎÀÇ Á¢¼ÓÀ» Â÷´ÜÇØ ³õÀº °æ¿ì¿¡µµ °ø°ÝÀ» ´çÇÒ ¼ö ÀÖ½À´Ï±î? - ¿ÜºÎ·Î ºÎÅÍÀÇ °ø°Ý¿¡´Â ºñ±³Àû ¾ÈÀüÇϳª ±â¾÷ ³»ºÎÀÚ¿¡ ÀÇÇÑ ±ÇÇÑ »ó½ÂÀº °¡´ÉÇϹǷΠÆÐÄ¡°¡ ¿ä¸ÁµË´Ï´Ù. ¤·¼³Ä¡½Ã ±âº»ÀûÀ¸·Î »ý¼ºµÇ´Â ¹Ì»ç¿ë °èÁ¤À» »èÁ¦Çϰųª ºñ¹Ð¹øÈ£¸¦ º¯°æÇÑ °æ¿ì ÆÐÄ¡¸¦ Àû¿ëÇÏÁö ¾Ê¾Æµµ µË´Ï±î? - ¹Ì»ç¿ë ±âº»°èÁ¤À» »èÁ¦ ¶Ç´Â ºñ¹Ð¹øÈ£¸¦ º¯°æÇÑ °æ¿ì¿¡µµ ÇØ´ç Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°Ý¿¡ ¾ÈÀüÇÒ ¼ö ¾øÀ¸´Ï ÆÐÄ¡¸¦ Àû¿ëÇϽô °ÍÀÌ ¹Ù¶÷Á÷ÇÕ´Ï´Ù. ¤·ÆÐÄ¡ Àû¿ë½Ã ±âÁ¸¿¡ ¼ºñ½ºÇÏ´ø ÀÀ¿ëÇÁ·Î±×·¥ ¾ÈÁ¤¼º¿¡´Â ¹®Á¦°¡ ¾ø³ª¿ä? - Oracle °í°´Áö¿ø¼¾ÅÍ ¹× À¯Áöº¸¼ö¾÷ü µîÀ» ÅëÇÏ¿© »çÀü °ËÁõÀ» ÇÏ°í ÆÐÄ¡¸¦ Àû¿ëÇϽô °ÍÀÌ ¹Ù¶÷Á÷ÇÕ´Ï´Ù.
|
|
|