Ãë¾àÁ¡ID |
28127 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â 7.0.4 ÀÌÀüÀÇ QuickTime Player ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î ³ªÅ¸³´Ù. AppleÀÇ QuickTime Player´Â ·ÎÄà ¹× ¿ø°ÝÁöÀÇ ¸ÖƼ¹Ìµð¾î ÄÜÅÙÃ÷¸¦ »ç¿ëÀÚµéÀÌ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â ¿¬ÁÖ±â(player)ÀÌ´Ù. QuickTime Player 7.0.4 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ QuickTime ÆÄÀÏ(.mov, QTIF, TGA, TIFF ȤÀº GIF À̹ÌÁö)À» ¾î¶² »ç¿ëÀÚ°¡ ½ÇÇàÇϵµ·Ï À¯µµÇÔÀ¸·Î½á, °ø°ÝÀÚ´Â QuickTimeÀ» Å©·¡½¬ ½ÃÅ°°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041289.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041290.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041291.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041292.html http://www.cirt.dk/advisories/cirt-41-advisory.pdf http://lists.apple.com/archives/security-announce/2006/Jan/msg00001.html http://docs.info.apple.com/article.html?artnum=303101 http://secunia.com/advisories/18149
http://www.security-protocols.com/advisory/sp-x21-advisory.txt
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apple Computer »ç, QuickTime Player 7.0.4 ÀÌÀüÀÇ ¹öÀüµé (for Windows) Apple Computer »ç, Mac OS 10.x Microsoft Windows Any version |
ÇØ°áÃ¥ |
Apple À¥ »çÀÌÆ®ÀÎ http://www.apple.com/quicktime/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â QuickTime PlayerÀÇ °¡Àå ÃֽŠ¹öÀü(7.0.4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-2340,CVE-2005-3707,CVE-2005-3708,CVE-2005-3709,CVE-2005-3710,CVE-2005-3711,CVE-2005-3713,CVE-2005-4092 (CVE) |
°ü·Ã URL |
16202 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|