Ãë¾àÁ¡ID |
28141 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
Skype ¼ÒÇÁÆ®¿þ¾îÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é, ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â Èü ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Skype´Â ¿Àµð¿À, ºñµð¿À, ±×¸®°í ´Ù¸¥ ¹Ìµð¾î ÆÄÀϵéÀ» °øÀ¯ÇÏ´Â µ¥ »ç¿ëµÇ´Â P2P ÆÄÀÏ °øÀ¯ ÇÁ·Î±×·¥À¸·Î IP ³×Æ®¿öÅ©µéÀ» ÅëÇØ ÀüÈ ¼ºñ½º¸¦ Á¦°øÇϱ⵵ ÇÑ´Ù. Skype 1.4.0.84 ÀÌÀüÀÇ ¹öÀüµéÀº ¸Å¿ì Å« Object Counter °ªÀ» °¡Áø Á¶ÀÛµÈ ³×Æ®¿öÅ© µ¥ÀÌÅ͸¦ ÅëÇØ Èü ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Skype°¡ Á¢¼Ó´ë±â ÁßÀÎ UDP ȤÀº TCP Æ÷Æ®µé·Î Àß Á¶ÀÛµÈ ³×Æ®¿öÅ© ÆÐŶÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Skype Ŭ¶óÀ̾ðÆ®¸¦ Å©·¡½¬ ½ÃÅ°°Å³ª ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/414519/30/0/threaded http://secunia.com/advisories/17305/ http://www.kb.cert.org/vuls/id/905177
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Skype Technologies »ç, Skype 1.4.0.84 ÀÌÀüÀÇ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
Skype À¥ »çÀÌÆ®ÀÎ http://www.skype.com/intl/en/get-skype/on-your-computer/windows/?intcmp=ch3-downloadSkype-side ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Skype for WindowsÀÇ ÃֽŠ¹öÀü(1.4.0.84 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-3265,CVE-2005-3267 (CVE) |
°ü·Ã URL |
15190,15192 (SecurityFocus) |
°ü·Ã URL |
22848,22849,22850 (ISS) |
|