Ãë¾àÁ¡ID |
23055 |
À§Çèµµ |
40 |
Æ÷Æ® |
554 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
RTSP |
»ó¼¼¼³¸í |
ÇØ´ç Helix Universal ¼¹ö´Â RTSP ÇÁ·ÎÅäÄÝ ÇØ¼®±â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. RealNetworksÀÇ Helix Universal ¼¹ö´Â ¸ðµç ÁÖ¿ä ¹Ìµð¾î ÆÄÀÏ À¯ÇüµéÀ» Áö¿øÇÏ´Â ½ºÆ®¸®¹Ö ¿Àµð¿À ¼¹öÀÌ´Ù. Helix Universal ¼¹ö 9 ÀÌÇÏÀÇ ¹öÀüµéÀº "View Source" Ç÷¯±×Àο¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ root ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ¼¹ö »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇÏ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¾î¶² Á¾·ùÀÇ ¹®ÀÚ¿µéÀÌ ¼¹öÀÇ ÇÁ·ÎÅäÄÝ ÇØ¼®±â·Î º¸³»Áø URLµé ³»ÀÇ ¾ÆÁÖ Å« ¼ýÀÚµé·Î Ç¥ÇöµÇ¾î Áú ¶§ ¹ß»ýÇÑ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Helix ¼¹öÀÇ ¹öÀü Á¤º¸¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/934932 http://service.real.com/help/faq/security/bufferoverrun030303.html http://www.service.real.com/help/faq/security/rootexploit091103.html http://www.service.real.com/help/faq/security/rootexploit082203.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: RealNetworks, Inc. Helix Universal Server 9.0 ÀÌÇÏÀÇ ¹öÀüµé Microsoft Windows Any version Various Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ RealNetworksÀÇ °í°´ Áö¿ø À¥ »çÀÌÆ®·ÎºÎÅÍ Helix Universal ServerÀÇ °¡Àå ÃֽйöÀü(9.0.2.802 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.service.real.com/help/faq/security/rootexploit091103.html
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, /Plugins µð·ºÅ丮·ÎºÎÅÍ "View Source" Ç÷¯±×ÀÎÀ» Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. Ç÷¯±×ÀÎÀº Àåºñ¿¡ µû¶ó ´ÙÀ½ ÆÄÀϸíµéÀ» °¡Áö°í ÀÖ´Ù: vsrcplin.so (UNIX) vsrcplin.dll (Windows)
±×·± ´ÙÀ½ ¼¹ö¸¦ Àç½ÃÀÛÇÏ¿©¾ß ÇÑ´Ù. Ç÷¯±×ÀÎÀ» Á¦°ÅÇÏ°Ô µÇ¸é Content Browsing ±â´ÉÀÌ ÀÛµ¿ ÁßÁöµÇ°Ô µÈ´Ù. |
°ü·Ã URL |
CVE-2003-0725 (CVE) |
°ü·Ã URL |
8476 (SecurityFocus) |
°ü·Ã URL |
13004 (ISS) |
|