English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23167
À§Çèµµ 40
Æ÷Æ® 5900, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í ÇØ´ç VNC ¼­¹ö´Â ÀÎÁõ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. VNC ÇÁ·ÎÅäÄÝÀº ±×·¡ÇÈ »ç¿ëÀÚ ÀÎÅÍÆäÀ̽ºµé¿¡ ´ëÇÑ ¿ø°Ý ¾×¼¼½º¸¦ À§ÇÑ °£´ÜÇÑ ÇÁ·ÎÅäÄÝÀÌ´Ù. RealVNC´Â VNC ÇÁ·ÎÅäÄÝÀÇ ±¸ÇöÀÌ´Ù. RealVNC Free Edition, Personal Edition, Enterprise Edition, ±×¸®°í AdderLink IP¿Í °°Àº RealVNC¸¦ ÀÌ¿ëÇÏ´Â ¿©·¯ Á¦Ç°µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÎÁõÀ» ¿ìȸÇÏ°í VNC ¼­¹ö¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ´Â Null ÀÎÁõ ¹æ¹ýÀ» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛÀ¸·Î °ø°ÝÀÚ¸¦ ¼º°øÀûÀ¸·Î ÀÎÁõÇØ Áִ Ŭ¶óÀ̾ðÆ® ÀÎÁõ ¹æ¹ýÀÇ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇØ ¹ß»ýÇÑ´Ù. ¸¸¾à VNC ¼­¹ö°¡ °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø ä ½ÇÇà ÁßÀ̶ó¸é °ø°ÝÀÚ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.realvnc.com/products/free/4.1/release-notes.html
http://www.realvnc.com/products/personal/4.2/release-notes.html
http://www.realvnc.com/products/enterprise/4.2/release-notes.html
http://www.intelliadmin.com/blog/2006/05/security-flaw-in-realvnc-411.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/046039.html
http://www.kb.cert.org/vuls/id/117929
http://secunia.com/advisories/20109/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Adder Technology, AdderLink IP versions 3.3 ÀÌÀüÀÇ ¹öÀüµé
RealVNC ȍ, RealVNC Enterprise Edition 4.2.2
RealVNC ȍ, RealVNC Free Edition 4.1.0
RealVNC ȍ, RealVNC Free Edition 4.1.1
RealVNC ȍ, RealVNC Personal Edition 4.2.2
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ RealVNC ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.realvnc.com/download.html ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â RealVNC Free Edition 4.1.2, Personal Edition 4.2.3, ȤÀº Enterprise Edition 4.2.3 ȤÀº ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

AdderLink IPÀÇ °æ¿ì:
Adder À¥ »çÀÌÆ®ÀÎ http://news.adder.com/uk/updates.aspx ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ Æß¿þ¾î ¹öÀü(3.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-2369 (CVE)
°ü·Ã URL 17978 (SecurityFocus)
°ü·Ã URL 26445 (ISS)