English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22293
À§Çèµµ 30
Æ÷Æ® 7070,8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Helix Universal ¼­¹öÀÇ ¹öÀü¿¡´Â ºñÁ¤»óÀûÀÎ POST ¿äû¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. RealNetworksÀÇ Helix Universal ¼­¹ö´Â ¸ðµç ÁÖ¿ä ¹Ìµð¾î ÆÄÀÏ À¯ÇüµéÀ» Áö¿øÇÏ´Â ½ºÆ®¸®¹Ö ¿Àµð¿À ¼­¹öÀÌ´Ù. Helix Universal ¼­¹ö 9.0.4.958 ÀÌÇÏÀÇ ¹öÀüµé°ú Helix Universal Mobile Server & Gateway 10.3.1.716 ÀÌÇÏÀÇ ¹öÀüµéÀº POST Çì´õÀÇ °ª¿¡ ´ëÇÑ À߸øµÈ 󸮷ΠÀÎÇØ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â ¼­¹ö°¡ ÄÄÇ»ÅÍ ÀÚ¿øÀ» ¸ðµÎ ¼ÒÁøÇÏ°Ô ÇÒ ¼ö ÀÖÀ¸¸ç ÀÌ´Â ½Ã½ºÅÛÀÌ ´Ù¿îµÇ°Å³ª Á¤»óÀûÀÎ »ç¿ëÀڵ鿡 ´ëÇÑ ¼­ºñ½º¸¦ ÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Helix Universal ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0182.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
RealNetworks, Inc., Helix Universal Server 9.0.4.958 ÀÌÇÏÀÇ ¹öÀüµé
RealNetworks, Inc., Helix Universal Mobile Server & Gateway 10.3.1.716 ÀÌÇÏÀÇ ¹öÀüµé
Linux Any version
Unix Any version
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ RealNetworks »çÀÇ º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© Helix Universal ServerÀÇ °¡Àå ÃֽйöÀü(Helix Universal Server 9.0.4.960 ȤÀº ÀÌÈÄ ±×¸®°í Helix Mobile Universal Server ¹× Gateway 10.04.1226 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://service.real.com/help/faq/security/security100704.html
°ü·Ã URL CVE-2004-0774 (CVE)
°ü·Ã URL 11352 (SecurityFocus)
°ü·Ã URL 17648 (ISS)