
CVE-2011-2461을 수정하기 위한 uploader.swf 및 uploaderSingle.swf의 패치된 버전
CVE-2011-2461을 수정하기 위해 패치된 uploader.swf 및 uploaderSingle.swf 버전입니다.
Magento 코어에 포함된 취약한 .swf 파일에 대한 자세한 정보는 여기에서 확인할 수 있습니다 - https://packetstormsecurity.com/files/131376/Magento-eCommerce-Vulnerable-Adobe-Flex-SDK.html
CVE-2011-2461의 핵심 원인은 @Mindedsecurity가 가장 잘 설명하고 있습니다. http://blog.mindedsecurity.com/2015/03/the-old-is-new-again-cve-2011-2461-is.html @sneak_ & @_ikki에게 감사드립니다.
파일은 공식 Adobe 패치 도구(Action I)로 패치되었습니다. https://helpx.adobe.com/flash-builder/kb/flex-security-issue-apsb11-25.html
ParrotNG(https://github.com/ikkisoft/ParrotNG)로 SWF 파일을 확인하고 공식 Adobe 패치 도구로 직접 패치할 수도 있습니다.