English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28192
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç Windows È£½ºÆ®¿¡´Â Cross-Site Scripting Ãë¾àÁ¡¿¡ Ãë¾àÇÑ Google DesktopÀÇ ¾î¶² ¹öÀüÀÌ Á¸ÀçÇÑ´Ù. Google DesktopÀº »ç¿ëÀÚµéÀÌ ÄÄÇ»ÅÍ »ó¿¡ ÀÖ´Â ÆÄÀϵéÀ» ½±°Ô °Ë»öÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â Microsfot Windows Ç÷§ÆûµéÀ» À§ÇÑ °Ë»ö ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Google Desktop 5.0.0701.30540 ÀÌÀüÀÇ ¹öÀüµéÀº under Àμö¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº Google Desktop °Ë»ö ¿£ÁøÀÌ »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÇÏ°Ô °É·¯³»Áö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁöÀÇ Àΰ¡¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â Google Desktop °Ë»ö ¿£ÁøÀÌ ¼öÇà°¡´ÉÇÑ ¹üÀ§³»ÀÇ ÀÓÀÇÀÇ ÇàÀ§¸¦ ¼öÇàÇÒ ¼ö ÀÖ´Ù. ÀÌ ÇàÀ§¿¡´Â ÆÄÀÏ °Ë»ö ¹× ³»¿ëº¸±â ±×¸®°í ¹Î°¨ÇÑ µ¥ÀÌÅÍ ²¨³»º¸±â¿Í °°Àº ÀÌ¹Ì Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÇÁ·Î±×·¥µéÀÇ ½ÇÇàÀ» Æ÷ÇÔÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/archive/1/460735/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/460928/100/0/threaded
http://www.kb.cert.org/vuls/id/615857
http://www.securitytracker.com/id?1017686

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Google Desktop 5.0.0701.30540 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Google DesktopÀº »õ·Î¿î ¹öÀüÀÇ ¼ÒÇÁÆ®¿þ¾î°¡ ³ª¿À¸é ½º½º·Î ÀÚµ¿ ¾÷µ¥ÀÌÆ®ÇØ ÁØ´Ù.

¸¸¾à ÀÚµ¿À¸·Î ¾÷µ¥ÀÌÆ®µÇÁö ¾Ê¾Ò´Ù¸é ¼öµ¿À¸·Î ´ÙÀ½ Google Desktop À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Google DesktopÀÇ °¡Àå ÃֽŠ¹öÀü(5.0.0701.30540 ȤÀº ÀÌÈÄ)À¸·Î ¼öµ¿ ¾÷µ¥ÀÌÆ®ÇÒ ¼ö ÀÖ´Ù:
http://desktop.google.com/?utm_campaign=en&utm_source=en-ha-na-us-google&utm_medium=ha&utm_term=google%20desktop
°ü·Ã URL CVE-2007-1085 (CVE)
°ü·Ã URL 22650 (SecurityFocus)
°ü·Ã URL 32735 (ISS)