Ãë¾àÁ¡ID |
28293 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â 11.5.9.620 ÀÌÀüÀÇ Shockwave PlayerÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Shockwave Player 11.5.9.620 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ°íÇ÷¯±×ÀÎ ÇüÅ·Π»ç¿ëÇÏ´Â À¥ ºê¶ó¿ìÀú´Â ÀÌ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ´Â´Ù.
¿ø°ÝÀÇ À©µµ¿ì È£½ºÆ®´Â 11.5.9.620 ÀÌÀüÀÇ Adobe Shockwave Player°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÇØ´ç ¹öÀüÀº ÀáÀçÀûÀ¸·Î ´ÙÀ½ÀÇ À̽´µé¿¡ ¿µÇâÀ» ¹Þ´Â´Ù :
- 'dirapi.dll'¿¡´Â ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÀ» Çã¿ëÇÏ´Â ´Ù¼öÀÇ Á¤ÀǵÇÁö ¾ÊÀº ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-2587, CVE-2010-2588, CVE-2010-4188)
- 'dirapi.dll' ¸ðµâ¿¡´Â Á¤¼öÇü ¿À¹öÇ÷οì¿Í ¿¬°üµÈ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÏ°í ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2010-2589)
- 'Settings'â°ú °ü·ÃµÈ ºÒƯÁ¤ÇÑ È£È¯¼º ±¸¼º¿ä¼Ò¿Í ºÒƯÁ¤ ¶óÀ̺귯¸®°¡ ¾ð·Îµå µÉ ¶§ use-after-free ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù°í ¾Ë·ÁÁ® ÀÖ´Ù. ÀÌ ¹®Á¦Á¡Àº ¾ÇÀÇÀûÀÎ À¥»çÀÌÆ®¿¡ ¹æ¹®ÇßÀ» ¶§ Ãæµ¹ÀÌ ¹ß»ýÇؼ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù°í º¸°íµÇ¾î ÀÖ´Ù. (CVE-2010-4092)
- ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇϰųª ¸Þ¸ð¸® ¼Õ»óÀ» ÀÏÀ¸Å°´Â ºÒƯÁ¤ÇÑ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. °ø°Ý ¿ä¼Ò´Â Á¤ÀǵÇÁö ¾Ê¾Ò´Ù. (CVE-2010-4093, CVE-2010-4187, CVE-2010-4190, CVE-2010-4191, CVE-2010-4192, CVE-2010-4306, CVE-2011-0555)
- GIF À̹ÌÁöÀÇ ÀüüÀûÀÎ »ö»ó Å×À̺íÀ» Æ÷ÇÔÇÏ´Â µð·ºÅÍ ¹«ºñ¸¦ ó¸®ÇÒ¶§ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â 'IML21'¸ðµâ¿¡¼ ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4189)
- ºÒ¸íÈ®ÇÑ ¿ä¼Ò¸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4193)
- ºÒ¸íÈ®ÇÑ ¿ä¼Ò¸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ºÒ¸íÈ®ÇÑ ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ 'dirapi.dll'¿¡¼ Á¸ÀçÇÑ´Ù. (CVE-2010-4194)
- '3D Assets' ¸ðµâ¿¡¼ ·¹ÄÚµå ŸÀÔ '0xFFFFFF45'¸¦ Æ÷ÇÔÇÏ´Â 3D ÀÚ»êÀ» ÆĽÌÇÒ¶§ Á¤¼öÇü ¿À¹öÇÃ·Î¿ì ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù. (CVE-2010-4196)
- ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ 'TextXtra.x32' ¸ðµâÀÇ ºÎºÐÀ» ºÐ¼®ÇÏ´Â 'DEMUX' ûũ¿¡¼ ¹ß»ýÇÑ´Ù. ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ °ÍÀÌ´Ù. (CVE-2010-4195)
- ºÒƯÁ¤ º¤Å͸¦ ÅëÇؼ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ¹öÆÛ ¿À¹öÇÃ·Î¿ì ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4307)
- 'Font Xtra.x32'ÀÇ ºÎºÐÀ» ÆĽÌÇÏ´Â 'PFR1' ûũ¿¡¼ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù. (CVE-2011-0556)
- ºÒƯÁ¤ º¤Å͸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº Á¤¼öÇü ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù. (CVE-2011-0557)
- ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â ºÎÈ£ ¾øÀ½°ú °ü·ÃµÈ ¹®Á¦Á¡ÀÌ 'Font Xtra.x32'¸ðµâ¿¡ Á¸ÀçÇÑ´Ù. (CVE-2011-0569)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.zerodayinitiative.com/advisories/ZDI-11-078/ http://www.zerodayinitiative.com/advisories/ZDI-11-079/ http://www.zerodayinitiative.com/advisories/ZDI-11-080/ http://www.adobe.com/support/security/bulletins/apsb11-01.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Shockwave Player 11.5.9.620 ÀÌÀü ¹öÀü Microsoft Windows Any version |
ÇØ°áÃ¥ |
Adobe À¥ »çÀÌÆ®ÀÎ http://get.adobe.com/shockwave/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Shockwave PlayerÀÇ °¡Àå ÃֽŠ¹öÀü(11.5.9.620 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2010-2587,CVE-2010-2588,CVE-2010-2589,CVE-2010-4092,CVE-2010-4093,CVE-2010-4187,CVE-2010-4188,CVE-2010-4189,CVE-2010-4190 (CVE) |
°ü·Ã URL |
44617,46284,46316,46317,46318,46319,46320,46321,46324,46325,46326,46327,46328,46329,46330,46332,46333,46334,46335,46336 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|