English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23197
À§Çèµµ 40
Æ÷Æ® 554
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù RTSP
»ó¼¼¼³¸í Darwin Streaming ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â µÎ°³ÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Apple Darwin Streaming Server´Â ¹Ìµð¾î ½ºÆ®¸®¹Ö ¼­¹öÀÌ´Ù. Darwin Streaming Server 5.5.5 ÀÌÀüÀÇ ¹öÀüµéÀº SETUP RTSP ¿äû¿¡¼­ÀÇ ´ÙÁßÀÇ trackID °ªµé, ±×¸®°í RTSP ¿äû¿¡¼­ÀÇ ±ä cmd ȤÀº server °ªÀ» ÅëÇÑ µÎ °³ÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ºñÀΰ¡µÈ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ RTSP ¿äûµéÀ» ÀÌ¿ëÇÏ¿© ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖÀ¸¸ç, ¿µÇâÀ» ¹Þ´Â ¼­ºñ½º¸¦ Å©·¡½¬½ÃÅ°°Å³ª Ç¥Àû ¼­ºñ½ºÀÇ ±ÇÇÑ, ´ë°³´Â root ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç RTSP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://docs.info.apple.com/article.html?artnum=305495
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533
http://securitytracker.com/alerts/2007/May/1018047.html
http://secunia.com/advisories/25193

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apple Computer »ç, Darwin Streaming Server 5.5.5 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Darwin Streaming Server À¥ ÆäÀÌÁöÀÎ http://docs.info.apple.com/article.html?artnum=305495 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Darwin Streaming ServerÀÇ °¡Àå ÃֽŠ¹öÀü(5.5.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2007-0748,CVE-2007-0749 (CVE)
°ü·Ã URL 23918 (SecurityFocus)
°ü·Ã URL 34225,34222 (ISS)