보안 권고문

Adobe 제품 보안 업데이트 권고

개요

 

Adobe 제품에서 발생하는 취약점을 해결하는 보안 업데이트를 발표하였습니다. 해당하는 제품 사용자는 최신 버전으로 업데이트 하시기 바랍니다.

 

대상 제품

 

CVE-2024-45114, CVE-2024-47450, CVE-2024-47451, CVE-2024-47452

  • Illustrator 2024 버전: ~ 28.7.1(포함) (Windows, macOS)

 

CVE-2024-47426, CVE-2024-47427, CVE-2024-47428, CVE-2024-47429, CVE-2024-47430, CVE-2024-47431, CVE-2024-47432, CVE-2024-47433, CVE-2024-47434, CVE-2024-49515, CVE-2024-49516, CVE-2024-49517, CVE-2024-49518, CVE-2024-49519, CVE-2024-49520, CVE-2024-49525

  • Adobe Substance 3D Painter 버전: ~ 10.1.0(포함)

 

CVE-2024-49514

  • Photoshop 2023 버전: ~ 24.7.3(포함) (Windows, macOS)
  • Photoshop 2024 버전: ~ 25.11(포함) (Windows, macOS)

 

CVE-2024-47441, CVE-2024-47442, CVE-2024-47443

  • Adobe After Effects 버전: ~ 24.6.2(포함) (Windows, macOS)
  • Adobe After Effects 버전: ~ 23.6.9(포함) (Windows, macOS)

 

CVE-2024-49507, CVE-2024-49508

  • Adobe InDesign 버전: ~ ID19.5(포함) (Windows, macOS)
  • Adobe InDesign 버전: ~ ID18.5.2(포함) (Windows, macOS)

 

CVE-2024-49509

  • Adobe InDesign 버전: ~ ID19.5(포함) (Windows, macOS)
  • Adobe InDesign 버전: ~ ID18.5.3(포함) (Windows, macOS)

 

CVE-2024-49521

  • Adobe Commerce 버전: ~ 3.2.5(포함)

 

 

해결된 취약점

 

현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 힙 기반 버퍼 오버플로 취약점(CVE-2024-47450, CVE-2024-49517, CVE-2024-49508, CVE-2024-49525, CVE-2024-49509, CVE-2024-49507, CVE-2024-47431, CVE-2024-47428)

현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 범위를 벗어난 쓰기 취약점(CVE-2024-45114, CVE-2024-47451, CVE-2024-47452, CVE-2024-47433, CVE-2024-47442, CVE-2024-49516, CVE-2024-49518, CVE-2024-49519, CVE-2024-47427, CVE-2024-47434, CVE-2024-47432, CVE-2024-47441, CVE-2024-47429, CVE-2024-47430, CVE-2024-47443, CVE-2024-49520)

현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 Integer Underflow(Wrap 또는 Wraparound) 취약점(CVE-2024-49514)

공격자가 임의의 코드를 실행할 수 있는 신뢰할 수 없는 검색 경로 취약점(CVE-2024-49515)

현재 사용자의 컨텍스트에서 임의의 코드 실행을 초래할 수 있는 Double Free 취약점(CVE-2024-47426)

보안 기능 우회로 이어질 수 있는 서버 측 요청 위조(SSRF) 취약점(CVE-2024-49521)

 

 

취약점 패치

 

최신 업데이트를 통해 취약점 패치가 제공되었습니다. 참고 사이트의 안내에 따라 최신 취약점 패치 버전으로 업데이트 하시기 바랍니다.

 

CVE-2024-45114, CVE-2024-47450, CVE-2024-47451, CVE-2024-47452

  • Illustrator 2024 버전: 28.7.2 (Windows, macOS)

 

CVE-2024-47426, CVE-2024-47427, CVE-2024-47428, CVE-2024-47429, CVE-2024-47430, CVE-2024-47431, CVE-2024-47432, CVE-2024-47433, CVE-2024-47434, CVE-2024-49515, CVE-2024-49516, CVE-2024-49517, CVE-2024-49518, CVE-2024-49519, CVE-2024-49520, CVE-2024-49525

  • Adobe Substance 3D Painter 버전: 10.1.1

 

CVE-2024-49514

  • Photoshop 2023 버전: 24.7.4 (Windows, macOS)
  • Photoshop 2024 버전: 25.12 (Windows, macOS)

 

CVE-2024-47441, CVE-2024-47442, CVE-2024-47443

  • Adobe After Effects 버전: 24.6.3 (Windows, macOS)
  • Adobe After Effects 버전: 25.0 (Windows, macOS)

 

CVE-2024-49507, CVE-2024-49508

  • Adobe InDesign 버전: ID20.0 (Windows, macOS)
  • Adobe InDesign 버전: ID18.5.3 (Windows, macOS)

 

CVE-2024-49509

  • Adobe InDesign 버전: ID20.0 (Windows, macOS)
  • Adobe InDesign 버전: ID18.5.4 (Windows, macOS)

 

CVE-2024-49521

  • Adobe Commerce 버전: 3.2.6

 

 

참고사이트

 

[1] Security update available for Adobe Commerce | APSB24-90

https://helpx.adobe.com/security/products/magento/apsb24-90.html

[2] Security updates available for Substance 3D Painter | APSB24-86

https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html

[3] Security update available for Adobe Photoshop | APSB24-89

https://helpx.adobe.com/security/products/photoshop/apsb24-89.html

[4] Security Updates Available for Adobe After Effects | APSB24-85

https://helpx.adobe.com/security/products/after_effects/apsb24-85.html

[5] Security Updates Available for Adobe Illustrator | APSB24-87

https://helpx.adobe.com/security/products/illustrator/apsb24-87.html

[6] Security Update Available for Adobe InDesign | APSB24-88

https://helpx.adobe.com/security/products/indesign/apsb24-88.html