Ãë¾àÁ¡ID |
28270 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
¿ø°ÝÀÇ À©µµ¿ì È£½ºÆ®¿¡ ¼³Ä¡µÈ SkypeÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é Skype ¼³Á¤ ÆÄÀÏ°ú º¸¾È Á¤Ã¥ÀÌ À§Ä¡¸¦ Á¤ÀÇÇÏ´Â URI Çڵ鷯ÀÇ ¡®/Datapath¡¯ ÀÎÀÚ¸¦ ó¸®ÇÏ´Â ºÎºÐ¿¡ ¹®Á¦°¡ ÀÖ´Ù. °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ Ưº°ÇÏ°Ô Á¶ÀÛµÈ ¸µÅ©¸¦ Ŭ¸¯Çϵµ·Ï ÇÑ´Ù¸é °ø°ÝÀÚ´Â ¿ø°ÝÀÇ DatapathÀÇ À§Ä¡¿¡ SMB °øÀ¯°¡ °¡´ÉÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. Â÷·Ê·Î man-in-the-middle °ø°Ý ¶Ç´Â Åëȱâ·Ï°ú °°ÀÌ ¹Î°¨ÇÑ Á¤º¸ÀÇ ³ëÃâÀ» À¯µµÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.security-assessment.com/files/advisories/Skype_URI_Handling_Vulnerability.pdf http://www.securityfocus.com/archive/1/510017/30/0/threaded
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Skype Technologies »ç, Skype 4.2.0.155 ÀÌÀüÀÇ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
Skype À¥ »çÀÌÆ®ÀÎ http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Skype for WindowsÀÇ ÃֽŠ¹öÀü(4.2.0.155 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
38699 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|