[2009년7월7일] MS 윈도우 Zero-Day 패치

[패치 다운로드] http://www.nshc.net/down/XPatch.exe (새 창으로 열기)

2009년 7월 7일 현재 중국에서 Microsoft DirectShow (msvidctl.dll) 의 취약점을
이용한 Zero-Day Exploit 이 출현하였습니다. 해당 취약점으로 인하여 인터넷 웹서핑
사용자들이 직간접적인 공격에 무방비로 노출되어 있으며 공격자는 시스템 권한을
획득할 수 있습니다. 현재 MS 에서 보안패치작업을 실시하고 있으나 배포시점까지
공격을 방어할 수 없으므로 임시적인 보안패치를 배포하는 바입니다.
해당 취약점은 여러 인터페이스에 걸쳐서 문제점을 안고있으므로 현재 알려진 공격
방법보다 곧바로 변종공격이 예상되고 있습니다. MS 의 공식적인 패치가 있기전까지
msvidctl.dll 의 사용을 금지하도록 조치하였습니다.
 

주의: 해당 컨트롤을 사용하지 못하도록 막는 과정에서 기존의 동영상 서비스를
      이용할 수 없는 경우가 발생할 수 있습니다. MS 의 공식패치가 업데이트되기
      이전까지 불편하시더라도 안전이 더 우선시되는 곳에서만 사용하시기 바랍니다.

[패치 다운로드] http://www.nshc.net/down/XPatch.exe (새 창으로 열기)
[출처] http://www.nshc.net/bbs.php?table=sub_nshc_04_01&query=view&uid=626 (새 창으로 열기)

Posted by N돌핀

2009/07/08 12:58 2009/07/08 12:58
, , , , , ,
Response
No Trackback , No Comment
RSS :
http://blog.nshc.net/rss/response/8

Secunia Weekly Summary - Issue: 2009-20

========================================================================

                 The Secunia Weekly Advisory Summary
                       2009-05-07 - 2009-05-14

                      This week: 54 advisories

========================================================================
Table of Contents:

1.....................................................Word From Secunia
2....................................................This Week In Brief
3...............................This Weeks Top Ten Most Read Advisories
4..................................................This Week in Numbers

========================================================================
1) Word From Secunia:

"System access" vulnerabilities discovered in popular software in 2008
by:

Secunia:              44 Vulnerabilities discovered

iDefense Labs:        24 Vulnerabilities discovered

IBM/ISS:              15 Vulnerabilities discovered

Google Security:      13 Vulnerabilities discovered

NGS Software:         12 Vulnerabilities discovered

CoreSecurity:         12 Vulnerabilities discovered

Fortinet:              9 Vulnerabilities discovered

DVLabs:                8 Vulnerabilities discovered

CERT/CC:               6 Vulnerabilities discovered

McAfee Avert Labs:     5 Vulnerabilities discovered

Total research papers issued by Secunia Research in 2008: 64
http://secunia.com/secunia_research/ (새 창으로 열기)


Are you sure you have all the necessary vulnerability intelligence
research you require to secure your systems?

Click here to learn more on how you can Stay Secure against newly
discovered vulnerabilities within your network:

http://secunia.com/advisories/business_solutions/ (새 창으로 열기)

========================================================================
2) This Week in Brief:

Multiple vulnerabilities have been reported in Microsoft PowerPoint,
which can be exploited by malicious people to compromise a user's
system.

For more information, refer to:
http://secunia.com/advisories/32428/ (새 창으로 열기)

 --

Some vulnerabilities have been reported in Apple Safari, which can be
exploited by malicious people to compromise a user's system.

For more information, refer to:
http://secunia.com/advisories/35056/ (새 창으로 열기)

 --

Apple has issued a security update for Mac OS X, which fixes multiple
vulnerabilities.

For more information, refer to:
http://secunia.com/advisories/35074/ (새 창으로 열기)

========================================================================
3) This Weeks Top Ten Most Read Advisories:

1.  [SA34012] Adobe Flash Player Multiple Vulnerabilities
2.  [SA34451] Sun Java JDK / JRE Multiple Vulnerabilities
3.  [SA34924] Adobe Reader JavaScript Methods Memory Corruption
4.  [SA32428] Microsoft PowerPoint Multiple Vulnerabilities
5.  [SA33901] Adobe Reader/Acrobat Multiple Vulnerabilities
6.  [SA34866] Mozilla Firefox "nsTextFrame::ClearTextRun()" Memory
             Corruption
7.  [SA20153] Microsoft Word Malformed Object Pointer Vulnerability
8.  [SA33954] Microsoft Excel Two Vulnerabilities
9.  [SA35021] Pango Glyph String Parsing Integer Overflow Vulnerability
10. [SA35014] Google Chrome Skia 2D Integer Overflow Vulnerabilities

========================================================================
4) This Week in Numbers

During the past week 54 Secunia Advisories have been released. All
Secunia customers have received immediate notification on the alerts
that affect their business.

This weeks Secunia Advisories had the following spread across platforms
and criticality ratings:

Platforms:
 Windows             :      9 Secunia Advisories
 Unix/Linux          :     22 Secunia Advisories
 Other               :      0 Secunia Advisories
 Cross platform      :     23 Secunia Advisories

Criticality Ratings:
 Extremely Critical  :      0 Secunia Advisories
 Highly Critical     :     12 Secunia Advisories
 Moderately Critical :     27 Secunia Advisories
 Less Critical       :     14 Secunia Advisories
 Not Critical        :      1 Secunia Advisory

========================================================================

Posted by N돌핀

2009/05/16 21:50 2009/05/16 21:50
Response
No Trackback , No Comment
RSS :
http://blog.nshc.net/rss/response/4