91.0.4472.101์ผ ์ทจ์•ฝ์  ์ˆ˜์ •์ด ํฌํ•จ๋œ Chrome 0 ์—…๋ฐ์ดํŠธ

Google์€ CVE-91.0.4472.101-14 ๋ฌธ์ œ๋ฅผ ํฌํ•จํ•˜์—ฌ ๊ณต๊ฒฉ์ž๊ฐ€ ์ด๋ฏธ ์ต์Šคํ”Œ๋กœ์ž‡(2021์ผ)์— ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” 30551๊ฐœ์˜ ์ทจ์•ฝ์ ์„ ์ˆ˜์ •ํ•˜๋Š” Chrome 0์— ๋Œ€ํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์•„์ง ๊ณต๊ฐœ๋˜์ง€ ์•Š์•˜์œผ๋ฉฐ, V8 JavaScript ์—”์ง„์˜ ์ž˜๋ชป๋œ ์œ ํ˜• ์ฒ˜๋ฆฌ(์œ ํ˜• ํ˜ผ๋ž€)๋กœ ์ธํ•ด ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•œ๋‹ค๋Š” ๊ฒƒ๋งŒ ์•Œ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

์ƒˆ ๋ฒ„์ „์€ ๋˜ํ•œ "Back"์„ ์‚ฌ์šฉํ•  ๋•Œ ์ฆ‰๊ฐ์ ์ธ ์ „ํ™˜์— ์‚ฌ์šฉ๋˜๋Š” ์ „ํ™˜ ์บ์‹œ(BFCache, Back-forward ์บ์‹œ)์—์„œ ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ํ•ด์ œํ•œ ํ›„(use-after-free) ๋ฉ”๋ชจ๋ฆฌ ์•ก์„ธ์Šค๋กœ ์ธํ•ด ๋ฐœ์ƒํ•˜๋Š” ๋˜ ๋‹ค๋ฅธ ์œ„ํ—˜ํ•œ ์ทจ์•ฝ์  CVE-2021-30544๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค. โ€ ๋ฒ„ํŠผ " ๋ฐ "์•ž์œผ๋กœ" ๋˜๋Š” ํ˜„์žฌ ์‚ฌ์ดํŠธ์—์„œ ์ด์ „์— ๋ณธ ํŽ˜์ด์ง€๋ฅผ ํƒ์ƒ‰ํ•  ๋•Œ. ๋ฌธ์ œ์—๋Š” ์‹ฌ๊ฐํ•œ ์œ„ํ—˜ ์ˆ˜์ค€์ด ์ง€์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์„ ์‚ฌ์šฉํ•˜๋ฉด ๋ชจ๋“  ์ˆ˜์ค€์˜ ๋ธŒ๋ผ์šฐ์ € ๋ณดํ˜ธ๋ฅผ ์šฐํšŒํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ ์ƒŒ๋“œ๋ฐ•์Šค ํ™˜๊ฒฝ ์™ธ๋ถ€์˜ ์‹œ์Šคํ…œ์—์„œ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ธฐ์— ์ถฉ๋ถ„ํ•˜๋‹ค๋Š” ๊ฒƒ์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€