English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28126
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í Musicmatch JukeboxÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Musicmatch Jukebox´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ CD, MP3, WMA, ±×¸®°í WAV ÆÄÀϵéÀ» ¿¬ÁÖÇÏ°í Á¦ÀÛÇϱâ À§ÇÑ À½¾Ç ¿¬ÁÖ±âÀÌ´Ù. Musicmatch Jukebox 10.00.2047 ÀÌÇÏÀÇ ¹öÀüµé ±×¸®°í 9.00.0159 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site ScriptingÀ» ¼öÇàÇÏ°í ÀÓÀÇÀÇ ÆÄÀϵéÀ» »ý¼º ȤÀº µ¤¾î¾²±â ÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µé¿¡ ´õÇÏ¿© ¼ÒÇÁÆ®¿þ¾îµéÀº ¶ÇÇÑ ¹öÆÛ ¿À¹öÇ÷οì Á¶°Ç¿¡µµ Ãë¾àÇÏ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2005/Apr/1013718.html
http://secunia.com/advisories/15087/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Musicmatch Jukebox ¹öÀü 10.00.2047°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Musicmatch Jukebox ¹öÀü 9.00.0159¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Musicmatch Jukebox ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.musicmatch-10.com/ ·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â Musicmatch JukeboxÀÇ °¡Àå ÃֽŠ¹öÀü(10.0.2048 ȤÀº 9.0.5066 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-1185,CVE-2005-1186,CVE-2005-1167,CVE-2005-1168 (CVE)
°ü·Ã URL 13167,13173,13174 (SecurityFocus)
°ü·Ã URL 20137,20243,20244 (ISS)