English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28094
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç RealOne/RealPlayerÀÇ ¹öÀü¿¡ µû¸£¸é ÇØ´ç Player¿¡´Â Skin ÆÄÀÏÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
RealOne / RealPlayer´Â Microsoft Windows Ç÷§Æûµé ±×¸®°í ´ëºÎºÐÀÇ Linux¿Í UnixÀ» À§ÇÑ ÀÎÅÍ³Ý ¹Ìµð¾î Àü¼Û¿ëÀ¸·Î ¸Å¿ì ±¤¹üÀ§ÇÏ°Ô »ç¿ëµÇ´Â Á¦Ç°µé ÁßÀÇ ÇϳªÀÌ´Ù. Microsoft Windows¸¦ À§ÇÑ RealPlayer 10.x 6.0.12.1053 ÀÌÇÏÀÇ ¹öÀüµé°ú RealOne Player 1 ±×¸®°í 2 ¹öÀüµéÀº Skin ÆÄÀÏ ÀúÀå¼Ò¿¡ Æ÷ÇÔµÈ ÆÄÀϸíµé¿¡ ´ëÇØ ¼öÇàµÇ´Â ºÎÀûÀýÇÑ ¹öÆÛ ±æÀÌ °Ë»ç·Î ÀÎÇÏ¿©, ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ Skin ÆÄÀÏÀ» ¸¸µé¾î ¾ÇÀÇÀûÀÎ À¥ »çÀÌÆ®¸¦ ¹æ¹®Çϰųª ȤÀº ¼öµ¿À¸·Î ¾ÇÀÇÀûÀÎ Skin ÆÄÀÏÀ» Àû¿ëÇÏ´Â Èñ»ýÀÚÀÇ ±ÇÇÑÀ¸·Î Èñ»ýÀÚÀÇ ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-10/0302.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
RealNetworks, Inc., RealOne Player 1.0
RealNetworks, Inc., RealOne Player 2.0
RealNetworks, Inc., RealPlayer 10.x (6.0.12.1053)
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ RealNetworks »çÀÇ 2004³â 10¿ù 26ÀÏÀÚ Releases Update¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.service.real.com/help/faq/security/041026_player/EN/
°ü·Ã URL CVE-2004-1094 (CVE)
°ü·Ã URL 11555 (SecurityFocus)
°ü·Ã URL 17879 (ISS)