English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28231
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 8.1.3 ÀÌÀüÀÇ Adobe ReaderÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Adobe Reader 8.1.3 ÀÌÀüÀÇ ¹öÀüµéÀº PDF ÆÄÀÏ ºä¾î(viewer)¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â À¥ »çÀÌÆ®¿¡ ¾ÇÀÇÀûÀÎ ÆäÀÌÁö¸¦ È£½ºÆÃÇϰųª HTML email·Î ¾ÇÀÇÀûÀÎ ÆäÀÌÁö¸¦ º¸³¿À¸·Î½á ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é °¡Àå ½É°¢ÇÑ °æ¿ì °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/secunia_research/2008-14/
http://www.coresecurity.com/content/adobe-reader-buffer-overflow
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=755
http://www.zerodayinitiative.com/advisories/ZDI-08-072
http://www.zerodayinitiative.com/advisories/ZDI-08-073
http://www.zerodayinitiative.com/advisories/ZDI-08-074
http://www.securityfocus.com/archive/1/498027/30/0/threaded
http://www.securityfocus.com/archive/1/498032/30/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2008-11/0073.html
http://archives.neohapsis.com/archives/fulldisclosure/2008-11/0074.html
http://archives.neohapsis.com/archives/fulldisclosure/2008-11/0075.html
http://archives.neohapsis.com/archives/fulldisclosure/2008-11/0076.html
http://www.adobe.com/support/security/bulletins/apsb08-19.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Adobe Reader 8.1.3 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Adobe º¸¾È °Ô½Ã¹°¿¡ ¼³¸íµÇ¾î ÀÖµíÀÌ Adobe ReaderÀÇ °¡Àå ÃֽŠ¹öÀü(8.1.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.adobe.com/support/security/bulletins/apsb08-19.html
°ü·Ã URL CVE-2008-2549,CVE-2008-2992,CVE-2008-4812,CVE-2008-4813,CVE-2008-4814,CVE-2008-4816,CVE-2008-4817 (CVE)
°ü·Ã URL 29420,30035,32100,32103,32105 (SecurityFocus)
°ü·Ã URL 42886 (ISS)