English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28133
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í "iTunes for Windows"ÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â ·ÎÄà ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Windows ¿ë Apple iTunes 4.7.1.30 ±×¸®°í iTunes 5´Â ÇÁ·Î±×·¥À» ½ÇÇàÇÏ´Â ¹æ¹ýÀ» ã¾Æ³»±â À§ÇØ "CreateProcess()"¿Í "CreateProcessAsUser()" ÇÔ¼öµéÀ» ÀÌ¿ëÇÏ¿© iTunes°¡ ÀÚü Helper ¾îÇø®ÄÉÀ̼ÇÀ» ¶ç¿ö ½Ã½ºÅÛ °æ·Î¸íµéÀ» °Ë»öÇÏ´Â °úÁ¤¿¡¼­ÀÇ ¿À·ù·Î ÀÎÇÏ¿©, ·ÎÄà °ø°ÝÀÚ°¡ »ó½ÂµÈ ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ·ÎÄà °ø°ÝÀÚ´Â ÀǵµµÈ ¾îÇø®ÄÉÀ̼ǰú °°Àº À̸§À» °¡Áø ¾ÇÀÇÀûÀÎ ÇÁ·Î±×·¥À» »ý¼ºÇÒ ¼ö ÀÖ´Ù. ¸¸¾à ±× ÇÁ·Î±×·¥ÀÌ Àû´çÇÑ µð·ºÅ丮¿¡ À§Ä¡ÇÏ°í iTunes helper ¾îÇø®ÄÉÀ̼ÇÀÌ Ç¥Àû »ç¿ëÀÚ¿¡ ÀÇÇØ ½ÇÇàµÈ´Ù¸é, ±× ¾ÇÀÇÀûÀÎ ÇÁ·Î±×·¥Àº Ç¥Àû »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ½ÇÇàµÇ°Ô µÈ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://lists.apple.com/archives/security-announce/2005/Nov/msg00001.html
http://www.securitytracker.com/alerts/2005/Nov/1015222.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041475.html
http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033909.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apple Computer »ç, iTunes 4.7.1.30 ±×¸®°í iTunes 5
Microsoft Windows Any version
ÇØ°áÃ¥ Apple ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.apple.com/itunes/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â "iTunes 6 for Windows"·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2938 (CVE)
°ü·Ã URL 15446 (SecurityFocus)
°ü·Ã URL 23094 (ISS)