English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28283
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç RealPlayer ¹öÀü¿¡ µû¸£¸é, RealPlayer ¿¡´Â ´Ù¼öÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
RealNetworks »çÀÇ RealPlayer ´Â Microsoft Windows Ç÷§Æû°ú ´ëºÎºÐÀÇ Linux, Unix °è¿­ ¿î¿µÃ¼Á¦ »ó¿¡¼­ µ¿ÀÛÇÏ´Â ½ºÆ®¸®¹Ö ¿Àµð¿À¿Í ºñµð¿À Ç÷¹À̾îÀÌ´Ù. ÀϺΠRealPlayer ¹öÀüµé¿¡´Â ´ÙÀ½°ú °°ÀÌ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

-¸®¾óÇ÷¹À̾î´Â º¯ÇüµÈ 'IVR' Æ÷ÀÎÅÍ À妽º ÄÚµå ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-2996)
-¸®¾óÇ÷¹ÀÌ¾î ¾×ƼºêX´Â ÀÎÁõµÇÁö ¾ÊÀº ÆÄÀÏ Á¢±Ù Ãë¾àÁ¡ÀÌ Á¸ÀçµÈ´Ù. (CVE-2010-3002)
-¸®¾óÇ÷¹À̾î 'QCP' ÆÄÀÏ ÆĽ̽à Á¤¼öÇü ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-0116)
-'MP4' ÄÁÅÙÃ÷ÀÇ 'YUV420'º¯È¯¿¡¼­ Ä¡¼ö¸¦ ó¸®ÇÏ´Â ¹æ¹ý¿¡ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-0117)
-¸®¾óÇ÷¹À̾îÀÇ 'QCP' ÆĽ̽à ÆQ±â¹Ý ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-0120)
-¿©·¯ ºê¶ó¿ìÀú âÀ» ¿©´Â°Í°ú °ü·ÃµÈ ActiveX IE Ç÷¯±×ÀÎ Ãë¾àÁ¡ÀÌ ÀÖ´Ù. (CVE-2010-3001)
-¸®¾óÇ÷¹À̾îÀÇ 'FLV' ÆĽ̽à ´ÙÁß Á¤¼öÇü ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-3000)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-10-166
http://www.zerodayinitiative.com/advisories/ZDI-10-167
http://secunia.com/secunia_research/2010-8/
http://secunia.com/secunia_research/2010-3/
http://secunia.com/secunia_research/2010-5/
http://service.real.com/realplayer/security/08262010_player/en/
ÇØ°áÃ¥ ´ÙÀ½ RealNetworks »çÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽŹöÀüÀÇ RealPlayer·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.realnetworks.com/products-services/realplayer.aspx
°ü·Ã URL CVE-2010-0116,CVE-2010-0117,CVE-2010-0120,CVE-2010-2996,CVE-2010-3000,CVE-2010-3001,CVE-2010-3002 (CVE)
°ü·Ã URL 42775 (SecurityFocus)
°ü·Ã URL (ISS)