English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28293
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 11.5.9.620 ÀÌÀüÀÇ Shockwave PlayerÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Shockwave Player 11.5.9.620 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ°íÇ÷¯±×ÀÎ ÇüÅ·Π»ç¿ëÇÏ´Â À¥ ºê¶ó¿ìÀú´Â ÀÌ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ´Â´Ù.

¿ø°ÝÀÇ À©µµ¿ì È£½ºÆ®´Â 11.5.9.620 ÀÌÀüÀÇ Adobe Shockwave Player°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
ÇØ´ç ¹öÀüÀº ÀáÀçÀûÀ¸·Î ´ÙÀ½ÀÇ À̽´µé¿¡ ¿µÇâÀ» ¹Þ´Â´Ù :

- 'dirapi.dll'¿¡´Â ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÀ» Çã¿ëÇÏ´Â ´Ù¼öÀÇ Á¤ÀǵÇÁö ¾ÊÀº ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-2587, CVE-2010-2588, CVE-2010-4188)

- 'dirapi.dll' ¸ðµâ¿¡´Â Á¤¼öÇü ¿À¹öÇ÷οì¿Í ¿¬°üµÈ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÏ°í ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2010-2589)

- 'Settings'â°ú °ü·ÃµÈ ºÒƯÁ¤ÇÑ È£È¯¼º ±¸¼º¿ä¼Ò¿Í ºÒƯÁ¤ ¶óÀ̺귯¸®°¡ ¾ð·Îµå µÉ ¶§ use-after-free ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù°í ¾Ë·ÁÁ® ÀÖ´Ù.
ÀÌ ¹®Á¦Á¡Àº ¾ÇÀÇÀûÀÎ À¥»çÀÌÆ®¿¡ ¹æ¹®ÇßÀ» ¶§ Ãæµ¹ÀÌ ¹ß»ýÇؼ­ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù°í º¸°íµÇ¾î ÀÖ´Ù.
(CVE-2010-4092)

- ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇϰųª ¸Þ¸ð¸® ¼Õ»óÀ» ÀÏÀ¸Å°´Â ºÒƯÁ¤ÇÑ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù.
°ø°Ý ¿ä¼Ò´Â Á¤ÀǵÇÁö ¾Ê¾Ò´Ù. (CVE-2010-4093, CVE-2010-4187,
CVE-2010-4190, CVE-2010-4191, CVE-2010-4192,
CVE-2010-4306, CVE-2011-0555)

- GIF À̹ÌÁöÀÇ ÀüüÀûÀÎ »ö»ó Å×À̺íÀ» Æ÷ÇÔÇÏ´Â µð·ºÅÍ ¹«ºñ¸¦ ó¸®ÇÒ¶§ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â 'IML21'¸ðµâ¿¡¼­ ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4189)

- ºÒ¸íÈ®ÇÑ ¿ä¼Ò¸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4193)

- ºÒ¸íÈ®ÇÑ ¿ä¼Ò¸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ºÒ¸íÈ®ÇÑ ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ 'dirapi.dll'¿¡¼­ Á¸ÀçÇÑ´Ù. (CVE-2010-4194)

- '3D Assets' ¸ðµâ¿¡¼­ ·¹ÄÚµå ŸÀÔ '0xFFFFFF45'¸¦ Æ÷ÇÔÇÏ´Â 3D ÀÚ»êÀ» ÆĽÌÇÒ¶§ Á¤¼öÇü ¿À¹öÇÃ·Î¿ì ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù. (CVE-2010-4196)

- ÀԷ°ª °ËÁõ ¹®Á¦Á¡ÀÌ 'TextXtra.x32' ¸ðµâÀÇ ºÎºÐÀ» ºÐ¼®ÇÏ´Â 'DEMUX' ûũ¿¡¼­ ¹ß»ýÇÑ´Ù.
ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ °ÍÀÌ´Ù. (CVE-2010-4195)

- ºÒƯÁ¤ º¤Å͸¦ ÅëÇؼ­ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº ¹öÆÛ ¿À¹öÇÃ·Î¿ì ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2010-4307)

- 'Font Xtra.x32'ÀÇ ºÎºÐÀ» ÆĽÌÇÏ´Â 'PFR1' ûũ¿¡¼­ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù.
ÀÌ ¹®Á¦Á¡Àº ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÑ´Ù. (CVE-2011-0556)

- ºÒƯÁ¤ º¤Å͸¦ ÅëÇØ ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â Á¤ÀǵÇÁö ¾ÊÀº Á¤¼öÇü ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù. (CVE-2011-0557)

- ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀ» Çã¿ëÇÏ´Â ºÎÈ£ ¾øÀ½°ú °ü·ÃµÈ ¹®Á¦Á¡ÀÌ 'Font Xtra.x32'¸ðµâ¿¡ Á¸ÀçÇÑ´Ù. (CVE-2011-0569)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-11-078/
http://www.zerodayinitiative.com/advisories/ZDI-11-079/
http://www.zerodayinitiative.com/advisories/ZDI-11-080/
http://www.adobe.com/support/security/bulletins/apsb11-01.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Shockwave Player 11.5.9.620 ÀÌÀü ¹öÀü
Microsoft Windows Any version
ÇØ°áÃ¥ Adobe À¥ »çÀÌÆ®ÀÎ http://get.adobe.com/shockwave/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Shockwave PlayerÀÇ °¡Àå ÃֽŠ¹öÀü(11.5.9.620 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2010-2587,CVE-2010-2588,CVE-2010-2589,CVE-2010-4092,CVE-2010-4093,CVE-2010-4187,CVE-2010-4188,CVE-2010-4189,CVE-2010-4190 (CVE)
°ü·Ã URL 44617,46284,46316,46317,46318,46319,46320,46321,46324,46325,46326,46327,46328,46329,46330,46332,46333,46334,46335,46336 (SecurityFocus)
°ü·Ã URL (ISS)