Linux Mint ํ”„๋กœ์ ํŠธ์—์„œ ๊ฐœ๋ฐœ๋œ Xreader ๋ฌธ์„œ ๋ทฐ์–ด์˜ ์ทจ์•ฝ์ 

Linux Mint ๋ฐฐํฌํŒ ๊ฐœ๋ฐœ์ž๊ฐ€ ๊ฐœ๋ฐœํ•œ Xreader ๋ฌธ์„œ ๋ทฐ์–ด์—์„œ ๋‘ ๊ฐ€์ง€ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ํŠน์ˆ˜ํ•˜๊ฒŒ ํฌ๋งท๋œ EPUB ๋ฐ CBT ํŒŒ์ผ์„ ์—ด ๋•Œ ์•…์„ฑ ์ฝ”๋“œ ์‹คํ–‰์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ Xreader 4.0.0, 3.8.5, 3.6.6, 3.2.3 ๋ฐ 2.6.5 ์—…๋ฐ์ดํŠธ์—์„œ ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์€ EPUB ๋ฐ CBT ํ˜•์‹์„ ๊ตฌ๋ฌธ ๋ถ„์„ํ•˜๋Š” ์ฝ”๋“œ์˜ ์˜ค๋ฅ˜๋กœ ์ธํ•ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. EPUB์˜ ๊ฒฝ์šฐ, ์ด ๋ฌธ์ œ(CVE-2023-44451)๋Š” ์ž„์‹œ ํŒŒ์ผ์ด ํฌํ•จ๋œ ๋””๋ ‰ํ„ฐ๋ฆฌ์˜ ๋‚ด์šฉ์„ ์••์ถ• ํ•ด์ œํ•˜๊ธฐ ์œ„ํ•œ ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋งค๊ฐœ๋ณ€์ˆ˜์—์„œ ํŠน์ˆ˜ ๋ฌธ์ž("../")๋ฅผ ์ œ๋Œ€๋กœ ์ด์Šค์ผ€์ดํ”„ ์ฒ˜๋ฆฌํ•˜์ง€ ๋ชปํ•˜๋Š” ๊ฒƒ๊ณผ ๊ด€๋ จ์ด ์žˆ์Šต๋‹ˆ๋‹ค. CBT์˜ ๊ฒฝ์šฐ, ์ด ์ทจ์•ฝ์ (CVE-2023-44452)์€ system() ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์™ธ๋ถ€ intltool_merge ๋ช…๋ น์„ ์‹คํ–‰ํ•  ๋•Œ ํŒŒ์ผ์˜ ์ •๋ฆฌ๋˜์ง€ ์•Š์€ ๊ฐ’์„ ์ธ์ˆ˜๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ๊ณผ ๊ด€๋ จ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€