English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28292
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ºôµå¹øÈ£¿¡ µû¸£¸é, ¿ø°ÝÀÇ À©µµ¿ì È£½ºÆ®¿¡ ¼³Ä¡µÈ RealPlayerÀÇ ¹öÀüÀº AVI Çì´õ¸¦ ó¸®ÇÒ ¶§ ÆQ ¼Õ»ó Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ´Â´Ù.
¿ø°ÝÀÇ °ø°ÝÀÚ´Â ÀÌ ¹®Á¦Á¡À» ÀÌ¿ëÇÏ¿© ¿ø°ÝÀÇ È£½ºÆ®¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ÇÀ» ½ÇÇàÇÏ°í ÀÖ´Â »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÑ´Ù

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-11-033/
http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0521.html
http://service.real.com/realplayer/security/01272011_player/en/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
RealPlayer for À©µµ¿ì Build 12.0.1.633

¢Â Á¶Ä¡¹æ¹ý (Eng)
Upgrade to the latest version available from the RealNetworks Web site at http://kr.real.com/?error=/plus

¢Â Á¶Ä¡¹æ¹ý (Kor)
´ÙÀ½ RealNetworks »çÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://kr.real.com/?error=/plus
ÇØ°áÃ¥ ´ÙÀ½ RealNetworks »çÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://kr.real.com/?error=/plus
°ü·Ã URL CVE-2010-4393 (CVE)
°ü·Ã URL 46047 (SecurityFocus)
°ü·Ã URL (ISS)