개요
Adobe 제품에서 발생하는 취약점을 해결하는 보안 업데이트를 발표하였습니다. 해당하는 제품 사용자는 최신 버전으로 업데이트 하시기 바랍니다.
대상 제품
CVE-2024-45114, CVE-2024-47450, CVE-2024-47451, CVE-2024-47452
- Illustrator 2024 버전: ~ 28.7.1(포함) (Windows, macOS)
CVE-2024-47426, CVE-2024-47427, CVE-2024-47428, CVE-2024-47429, CVE-2024-47430, CVE-2024-47431, CVE-2024-47432, CVE-2024-47433, CVE-2024-47434, CVE-2024-49515, CVE-2024-49516, CVE-2024-49517, CVE-2024-49518, CVE-2024-49519, CVE-2024-49520, CVE-2024-49525
- Adobe Substance 3D Painter 버전: ~ 10.1.0(포함)
CVE-2024-49514
- Photoshop 2023 버전: ~ 24.7.3(포함) (Windows, macOS)
- Photoshop 2024 버전: ~ 25.11(포함) (Windows, macOS)
CVE-2024-47441, CVE-2024-47442, CVE-2024-47443
- Adobe After Effects 버전: ~ 24.6.2(포함) (Windows, macOS)
- Adobe After Effects 버전: ~ 23.6.9(포함) (Windows, macOS)
CVE-2024-49507, CVE-2024-49508
- Adobe InDesign 버전: ~ ID19.5(포함) (Windows, macOS)
- Adobe InDesign 버전: ~ ID18.5.2(포함) (Windows, macOS)
CVE-2024-49509
- Adobe InDesign 버전: ~ ID19.5(포함) (Windows, macOS)
- Adobe InDesign 버전: ~ ID18.5.3(포함) (Windows, macOS)
CVE-2024-49521
- Adobe Commerce 버전: ~ 3.2.5(포함)
해결된 취약점
현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 힙 기반 버퍼 오버플로 취약점(CVE-2024-47450, CVE-2024-49517, CVE-2024-49508, CVE-2024-49525, CVE-2024-49509, CVE-2024-49507, CVE-2024-47431, CVE-2024-47428)
현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 범위를 벗어난 쓰기 취약점(CVE-2024-45114, CVE-2024-47451, CVE-2024-47452, CVE-2024-47433, CVE-2024-47442, CVE-2024-49516, CVE-2024-49518, CVE-2024-49519, CVE-2024-47427, CVE-2024-47434, CVE-2024-47432, CVE-2024-47441, CVE-2024-47429, CVE-2024-47430, CVE-2024-47443, CVE-2024-49520)
현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 Integer Underflow(Wrap 또는 Wraparound) 취약점(CVE-2024-49514)
공격자가 임의의 코드를 실행할 수 있는 신뢰할 수 없는 검색 경로 취약점(CVE-2024-49515)
현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 Double Free 취약점(CVE-2024-47426)
보안 기능 우회로 이어질 수 있는 서버 측 요청 위조(SSRF) 취약점(CVE-2024-49521)
취약점 패치
최신 업데이트를 통해 취약점 패치가 제공되었습니다. 참고 사이트의 안내에 따라 최신 취약점 패치 버전으로 업데이트 하시기 바랍니다.
CVE-2024-45114, CVE-2024-47450, CVE-2024-47451, CVE-2024-47452
- Illustrator 2024 버전: 28.7.2 (Windows, macOS)
CVE-2024-47426, CVE-2024-47427, CVE-2024-47428, CVE-2024-47429, CVE-2024-47430, CVE-2024-47431, CVE-2024-47432, CVE-2024-47433, CVE-2024-47434, CVE-2024-49515, CVE-2024-49516, CVE-2024-49517, CVE-2024-49518, CVE-2024-49519, CVE-2024-49520, CVE-2024-49525
- Adobe Substance 3D Painter 버전: 10.1.1
CVE-2024-49514
- Photoshop 2023 버전: 24.7.4 (Windows, macOS)
- Photoshop 2024 버전: 25.12 (Windows, macOS)
CVE-2024-47441, CVE-2024-47442, CVE-2024-47443
- Adobe After Effects 버전: 24.6.3 (Windows, macOS)
- Adobe After Effects 버전: 25.0 (Windows, macOS)
CVE-2024-49507, CVE-2024-49508
- Adobe InDesign 버전: ID20.0 (Windows, macOS)
- Adobe InDesign 버전: ID18.5.3 (Windows, macOS)
CVE-2024-49509
- Adobe InDesign 버전: ID20.0 (Windows, macOS)
- Adobe InDesign 버전: ID18.5.4 (Windows, macOS)
CVE-2024-49521
- Adobe Commerce 버전: 3.2.6
참고사이트
[1] Security update available for Adobe Commerce | APSB24-90
https://helpx.adobe.com/security/products/magento/apsb24-90.html
[2] Security updates available for Substance 3D Painter | APSB24-86
https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html
[3] Security update available for Adobe Photoshop | APSB24-89
https://helpx.adobe.com/security/products/photoshop/apsb24-89.html
[4] Security Updates Available for Adobe After Effects | APSB24-85
https://helpx.adobe.com/security/products/after_effects/apsb24-85.html
[5] Security Updates Available for Adobe Illustrator | APSB24-87
https://helpx.adobe.com/security/products/illustrator/apsb24-87.html
[6] Security Update Available for Adobe InDesign | APSB24-88
https://helpx.adobe.com/security/products/indesign/apsb24-88.html