Ãë¾àÁ¡ID |
28133 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
"iTunes for Windows"ÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â ·ÎÄà ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Windows ¿ë Apple iTunes 4.7.1.30 ±×¸®°í iTunes 5´Â ÇÁ·Î±×·¥À» ½ÇÇàÇÏ´Â ¹æ¹ýÀ» ã¾Æ³»±â À§ÇØ "CreateProcess()"¿Í "CreateProcessAsUser()" ÇÔ¼öµéÀ» ÀÌ¿ëÇÏ¿© iTunes°¡ ÀÚü Helper ¾îÇø®ÄÉÀ̼ÇÀ» ¶ç¿ö ½Ã½ºÅÛ °æ·Î¸íµéÀ» °Ë»öÇÏ´Â °úÁ¤¿¡¼ÀÇ ¿À·ù·Î ÀÎÇÏ¿©, ·ÎÄà °ø°ÝÀÚ°¡ »ó½ÂµÈ ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ·ÎÄà °ø°ÝÀÚ´Â ÀǵµµÈ ¾îÇø®ÄÉÀ̼ǰú °°Àº À̸§À» °¡Áø ¾ÇÀÇÀûÀÎ ÇÁ·Î±×·¥À» »ý¼ºÇÒ ¼ö ÀÖ´Ù. ¸¸¾à ±× ÇÁ·Î±×·¥ÀÌ Àû´çÇÑ µð·ºÅ丮¿¡ À§Ä¡ÇÏ°í iTunes helper ¾îÇø®ÄÉÀ̼ÇÀÌ Ç¥Àû »ç¿ëÀÚ¿¡ ÀÇÇØ ½ÇÇàµÈ´Ù¸é, ±× ¾ÇÀÇÀûÀÎ ÇÁ·Î±×·¥Àº Ç¥Àû »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ½ÇÇàµÇ°Ô µÈ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://lists.apple.com/archives/security-announce/2005/Nov/msg00001.html http://www.securitytracker.com/alerts/2005/Nov/1015222.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041475.html http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033909.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apple Computer »ç, iTunes 4.7.1.30 ±×¸®°í iTunes 5 Microsoft Windows Any version |
ÇØ°áÃ¥ |
Apple ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.apple.com/itunes/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â "iTunes 6 for Windows"·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-2938 (CVE) |
°ü·Ã URL |
15446 (SecurityFocus) |
°ü·Ã URL |
23094 (ISS) |
|