Skip to content

Commit e1871c4

Browse files
waguranomarocchino
authored andcommitted
Translate 'Multiple vulnerabilities in RubyGems' (ko) (ruby#1630)
1 parent 790dcee commit e1871c4

File tree

1 file changed

+59
-0
lines changed

1 file changed

+59
-0
lines changed
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
layout: news_post
3+
title: "RubyGems์˜ ์ทจ์•ฝ์  ๋‹ค์ˆ˜ ๋ฐœ๊ฒฌ"
4+
author: "usa"
5+
translator: "wagurano"
6+
date: 2017-08-29 12:00:00 +0000
7+
tags: security
8+
lang: ko
9+
---
10+
11+
๋ฃจ๋น„ ๋ถ€๊ฐ€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์ธ RubyGems์˜ ์ทจ์•ฝ์  ๋‹ค์ˆ˜๊ฐ€ ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
12+
[RubyGems ๊ณต์‹ ๋ธ”๋กœ๊ทธ](http://blog.rubygems.org/2017/08/27/2.6.13-released.html)์— ๋ณด๊ณ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
13+
14+
## ์„ธ๋ถ€ ๋‚ด์šฉ
15+
16+
์•„๋ž˜์™€ ๊ฐ™์€ ์ทจ์•ฝ์ ์ด ๋ณด๊ณ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
17+
18+
* DNS ์š”์ฒญ ํ•˜์ด์žฌํ‚น ์ทจ์•ฝ์ . (CVE-2017-0902)
19+
* ANSI ์ด์Šค์ผ€์ดํ”„ ์‹œํ€€์Šค ์ทจ์•ฝ์ . (CVE-2017-0899)
20+
* ์งˆ์˜ ๋ช…๋ น์˜ DoS ์ทจ์•ฝ์ . (CVE-2017-0900)
21+
* ์•…์„ฑ ์ ฌ์ด ์ž„์˜์˜ ํŒŒ์ผ์„ ๋ฎ์–ด ์จ๋„ ๋ฃจ๋น„ ์ธ์Šคํ†จ๋Ÿฌ๊ฐ€ ํ—ˆ์šฉํ•˜๋Š” ์ทจ์•ฝ์ . (CVE-2017-0901)
22+
23+
๋ฃจ๋น„ ์‚ฌ์šฉ์ž๋Š” ๊ฐ€๋Šฅํ•œ ๋นจ๋ฆฌ ์•„๋ž˜ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์œผ๋กœ ์กฐ์น˜ํ•˜๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.
24+
25+
## ํ•ด๋‹น ๋ฒ„์ „
26+
27+
* ๋ฃจ๋น„ 2.2 ๋ฒ„์ „๋Œ€: 2.2.7 ์ดํ•˜
28+
* ๋ฃจ๋น„ 2.3 ๋ฒ„์ „๋Œ€: 2.3.4 ์ดํ•˜
29+
* ๋ฃจ๋น„ 2.4 ๋ฒ„์ „๋Œ€: 2.4.1 ์ดํ•˜
30+
* ๋ฆฌ๋น„์ „ 59672 ์ด์ „์˜ ํŠธ๋ ํฌ
31+
32+
## ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•
33+
34+
์—…๋ฐ์ดํŠธ๋œ RubyGems ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๋Š” ๋ฃจ๋น„ ๋ฆด๋ฆฌ์Šค ๋ฒ„์ „์€ ์—†์ง€๋งŒ,
35+
RubyGems๋ฅผ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
36+
RubyGems 2.6.13 ์ดํ›„ ๋ฒ„์ „์€ ์ทจ์•ฝ์ ์„ ๋ณด์™„ํ•˜์˜€์Šต๋‹ˆ๋‹ค.
37+
38+
```
39+
gem update --system
40+
```
41+
42+
RubyGems๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œ๋ฅผ ํ•  ์ˆ˜ ์—†๋‹ค๋ฉด, ์ฐจ์„ ์ฑ…์œผ๋กœ ๋‹ค์Œ ํŒจ์น˜๋ฅผ ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
43+
44+
* [๋ฃจ๋น„ 2.2.7](https://bugs.ruby-lang.org/attachments/download/6690/rubygems-2613-ruby22.patch)
45+
* [๋ฃจ๋น„ 2.3.4](https://bugs.ruby-lang.org/attachments/download/6691/rubygems-2613-ruby23.patch)
46+
* ๋ฃจ๋น„ 2.4.1: ํŒจ์น˜ 2๊ฐœ ํ•„์š”. ์•„๋ž˜ ์ˆœ์„œ๋Œ€๋กœ ์ ์šฉ:
47+
1. [RubyGems 2.6.11์—์„œ 2.6.12๋กœ ํŒจ์น˜](https://bugs.ruby-lang.org/attachments/download/6692/rubygems-2612-ruby24.patch)
48+
2. [RubyGems 2.6.12์—์„œ 2.6.13์œผ๋กœ ํŒจ์น˜](https://bugs.ruby-lang.org/attachments/download/6693/rubygems-2613-ruby24.patch)
49+
50+
๊ฐœ๋ฐœ๋ฒ„์ „์— ๋Œ€ํ•˜์—ฌ๋Š”, ์ตœ์‹  ๋ฆฌ๋น„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
51+
52+
## ๋„์›€์„ ์ค€ ๊ธ€
53+
54+
์ด ๋ณด๊ณ ์„œ๋Š” [RubyGems ๊ณต์‹ ๋ธ”๋กœ๊ทธ](http://blog.rubygems.org/2017/08/27/2.6.13-released.html)๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ํ•˜์—ฌ ์ž‘์„ฑํ•˜์˜€์Šต๋‹ˆ๋‹ค.
55+
56+
## ์ˆ˜์ • ์ด๋ ฅ
57+
58+
* 2017-08-29 21:00:00 (KST) ์ตœ์ดˆ ๊ณต๊ฐœ
59+
* 2017-08-31 11:00:00 (KST) CVE ๋ฒˆํ˜ธ ์ถ”๊ฐ€

0 commit comments

Comments
ย (0)