English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28138
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 6.0.12.1483 ÀÌÀüÀÇ RealOne/RealPlayerÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. RealOne / RealPlayer´Â Microsoft Windows Ç÷§Æûµé ±×¸®°í ´ëºÎºÐÀÇ Linux¿Í UnixÀ» À§ÇÑ ÀÎÅÍ³Ý ¹Ìµð¾î Àü¼Û¿ëÀ¸·Î ¸Å¿ì ±¤¹üÀ§ÇÏ°Ô »ç¿ëµÇ´Â Á¦Ç°µé ÁßÀÇ ÇϳªÀÌ´Ù. RealPlayer 8, 10, 10.5 ¹öÀüµé ±×¸®°í Enterprise 1.x, RealOne Player ¹öÀü 1°ú 2, ±×¸®°í Helix Player 10.0.x ¹öÀüµéÀº ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¾ÇÀÇÀûÀÎ SWF ȤÀº MBC ÆÄÀÏÀ» º¸³» »ç¿ëÀÚ°¡ ±× ÆÄÀÏÀ» ¿­¾î º¸°Ô²û À¯µµÇÔÀ¸·Î½á, °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇ÷οì½ÃÅ°°í ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ÇÀÌ ¼öÇàÇÏ´Â »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://service.real.com/realplayer/security/03162006_player/en/
http://secunia.com/advisories/19358/
http://securitytracker.com/alerts/2006/Mar/1015806.html
http://securitytracker.com/alerts/2006/Mar/1015808.html
http://securitytracker.com/alerts/2006/Mar/1015810.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
RealNetworks ȍ, Helix Player 10.0.0 - 10.0.5
RealNetworks ȍ, RealOne Player 1.0, 2.0
RealNetworks ȍ, RealOne Player for Mac Any version
RealNetworks ȍ, RealPlayer 10
RealNetworks »ç, RealPlayer 10.5 (6.0.12.1483 ÀÌÀüÀÇ 6.0.x)
RealNetworks ȍ, RealPlayer 8.0
RealNetworks ȍ, RealPlayer Enterprise 1.x
Microsoft Windows Any version
Linux Any version
Apple Mac OS Any version
ÇØ°áÃ¥ RealOne ±×¸®°í RealPlayerÀÇ °æ¿ì:
´ÙÀ½ 2006³â 3¿ù 16ÀÏÀÚ RealNetworkÀÇ Customer Support Release Update·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» À§ÇÑ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.service.real.com/realplayer/security/03162006_player/en/

RealPlayer EnterpriseÀÇ °æ¿ì:
´ÙÀ½ 2006³â 3¿ù 16ÀÏÀÚ RealNetworkÀÇ Security Patch Update·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» À§ÇÑ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.service.real.com/realplayer/security/security/enterprise_031606.html

Helix PlayerÀÇ °æ¿ì:
´ÙÀ½ Helix Player Community ´Ù¿î·Îµå À¥ ÆäÀÌÁö·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» À§ÇÑ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
https://player.helixcommunity.org/downloads/

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2005-2922,CVE-2005-2936,CVE-2006-0323,CVE-2006-1370 (CVE)
°ü·Ã URL 17202 (SecurityFocus)
°ü·Ã URL 23094,25408,25409,25411 (ISS)