| 
   
            
 	            | Ãë¾àÁ¡ID | 28110 |   
 	            | À§Çèµµ | 40 |  
 	            | Æ÷Æ® | 139,445 |  	
 	            | ÇÁ·ÎÅäÄÝ | TCP |  	
 	            | ºÐ·ù | SMB |  	
 	            | »ó¼¼¼³¸í | QuickTime PlayerÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â PictureViewer¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. AppleÀÇ QuickTime Player´Â ·ÎÄà ¹× ¿ø°ÝÁöÀÇ ¸ÖƼ¹Ìµð¾î ÄÜÅÙÃ÷¸¦ »ç¿ëÀÚµéÀÌ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â ¿¬ÁÖ±â(player)ÀÌ´Ù. QuickTimeÀÇ ¼³ºñ¸¦ ÀÌ¿ëÇϰíÀÚ ÇÏ´Â À¥ ºê¶ó¿ìÀú¿Í °°Àº ´Ù¸¥ ¿©·¯ ¾îÇø®ÄÉÀ̼ǵéÀº QuickTime È®Àå (QuickTime.qts) ±¸¼º¿ä¼Ò¸¦ »ç¿ëÇÏ¿©¾ß ÇÑ´Ù. Apple QuickTime ¹öÀü 6.5¿¡ ÀÖ´Â ÀÌ ±¸¼º¿ä¼Ò´Â Sample-to-Chunk Å×ÀÌºí ¿£Æ®¸®µéÀ» ¾î¶² ¹è¿¿¡ º¹»ç¸¦ ´ã´çÇÏ´Â ·çƾ¿¡ Èü(heap) ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Àß Á¶ÀÛµÈ QuickTime ÆÄÀÏ(.mov ÆÄÀÏ)À» »ç¿ëÀÚ°¡ ½ÇÇàÇϵµ·Ï À¯µµÇÔÀ¸·Î½á, °ø°ÝÀÚ´Â QuickTimeÀ» Å©·¡½¬ ½ÃŰ°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. 
 * ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
 
 * Âü°í »çÀÌÆ®:
 http://www.kb.cert.org/vuls/id/782958
 http://secunia.com/advisories/11071/
 http://www.securitytracker.com/alerts/2004/Apr/1010010.html
 http://www.securiteam.com/windowsntfocus/5NP020KCVU.html
 http://developer.apple.com/documentation/QuickTime/QTFF/index.html
 
 * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
 Apple Computer ȍ, QuickTime Player 6.5
 Apple Computer ȍ, iTunes 4.2.0.72
 Apple Computer ȍ, Mac OS 10.x
 Microsoft Windows Any version
 |  	
 	            | ÇØ°áÃ¥ | Apple À¥ »çÀÌÆ®ÀÎ http://www.apple.com/quicktime/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â QuickTime PlayerÀÇ °¡Àå ÃֽйöÀü(6.5.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |  	
 	            | °ü·Ã URL | CVE-2004-0431 (CVE) |  	
 	            | °ü·Ã URL | 12905 (SecurityFocus) |  
 	            | °ü·Ã URL | 16026 (ISS) |  |