채팅하기
Loader
연결을 설정 중입니다. 연결하는 동안 잠시 기다려 주십시오.

유령 및 멜트다운 보안 취약점 업데이트

유령과 붕괴란?

Spectre and Meltdown are vulnerabilities that can be exploited as speculative execution side-channel attacks executed by malware. There are no known active exploits of either Spectre or Meltdown.

  • Spectre steals data from the memory of other applications running on a machine. It affects almost all modern processors - including those from AMD, ARM, and Intel.

  • Meltdown enables reading protected memory. It can be easily fixed by OS updates and seems to be limited to Intel chips.
어떤 제품이 영향을 받는가요?

영향을 받는 제품 및 패치 릴리스 일정에 대한 추가 정보 페이지를 확인하십시오.

패치 릴리스 날짜가 설정되면 페이지가 계속 업데이트됩니다.

Zebra는 무엇을 권장하나요?

Zebra encourages customers to develop and maintain a regular software maintenance program. Zebra is actively working with operating system and processor vendors to provide remediation in a timely manner.

Zebra devices capable of running application code should be locked down to prevent loading of a malicious application that could attempt to exploit the vulnerabilities. Impacts from malicious code utilizing either Spectre or Meltdown can be mitigated by only loading application code from trusted sources. There are no reports of any successful reproduction of these vulnerabilities leading to a security issue on ARM or Intel based Android devices.

  • Android based products with a 2018-01-05 security patch level will be updated for the remaining mitigations of CVE-2017-13218 as required for compliance to the 2018-03-05 security patch level. Zebra mobile computing devices may be protected through a locked down configuration or by using Enterprise Home Screen to limit what applications can be launched. Zebra Android device update schedule

  • Microsoft-based products under Microsoft support will be updated by Microsoft. Windows CE and Windows Mobile operating systems are under investigation. See Microsoft's Spectre/Meltdown page for further information. 

  • Printer products potentially affected by the Spectre vulnerability are limited to the ZT510, ZT610 and ZT620. All other printer products currently deployed use a processor core that is not affected by Spectre. While the ZT510, ZT610 and ZT620 are potentially affected by Spectre, they are not directly impacted since the printer can only execute Zebra authored code. Zebra printers are not susceptible to Meltdown. 

  • Zebra OneCare Premier (Managed Service) customer devices eligible for upgrades can be scheduled as part of the customers contracted release management entitlement. Zebra-provided services employing cloud infrastructure are being updated as patches become available. 

 

참조 번호
01-0118-01

취약점 릴리스 날짜
1월 03일-2018일

  • 변형 1 - CVE-2017-5753, 유령: 경계 확인 바이패스

  • 변종 2 - CVE-2017-5715, 유령: 분기 대상 주입

  • 변형 3 - CVE-2017-5754, 멜트다운: 악성 데이터 캐시 로드, 커널 메모리 읽기 후 수행된 메모리 액세스 권한 확인

  • CVE-2017-13218이 문제를 해결 하는 사이드 채널 공격에 대 한 일반적인 경우 완화.

Disclaimer: Zebra makes every attempt to release security updates on or about the time that Google releases its respective security bulletin. However, delivery time of security updates may vary depending on the region, product model, and third party software suppliers. Under some circumstances, the OS must be updated to the latest maintenance release prior to installing the security updates. Individual product updates will provide specific guidance.

달리 명시되지 않는 한, 새로 보고된 문제로부터 의한 적극적인 고객 착취 또는 남용에 대한 보고는 없었습니다.



Zebra Technologies 제품의 잠재적인 보안 문제를 알고 있습니까?