English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50010
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 7.7.1 ÀÌÀüÀÇ QuickTime ÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. QuickTime 7.7.1 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- 'Save for Web' ³»º¸³»±â ±â´ÉÀ¸·Î ¸¸µé¾îÁø HTML ÆÄÀÏ¿¡´Â Å©·Î½º »çÀÌÆ® ½ºÅ©¸³Æà À̽´°¡ ÀÖ´Ù. (CVE-2011-3218)
- H.264·Î ÀÎÄÚµùµÈ ºñµð¿À ÆÄÀÏ Çڵ鸵½Ã ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. (CVE-2011-3219)
- ¹«ºñ ÆÄÀÏ¿¡¼­ URL µ¥ÀÌÅÍ Çڵ鷯¸¦ ó¸®ÇÒ ¶§ ¿À·ù°¡ Á¸ÀçÇÏ°í Á¤ÀǵÇÁö ¾ÊÀº Áö¿ªÀÇ ¸Þ¸ð¸®¿¡ Á¢±ÙÀ» Çã¿ëÇÑ´Ù. (CVE-2011-3220)
- ºñµð¿À ÆÄÀÏÀÇ 'TKHD atoms' »Ó¸¸ ¾Æ´Ï¶ó 'atoms' ±¸Á¶¸¦ Çڵ鸵ÇÒ¶§ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2011-3221, CVE-2011-3251)
- FlashPix, FLIC, PICT¿Í FLC-ÀÎÄÚµùµÈ ÆÄÀÏÀ» ó¸®ÇÒ ¶§ ¹öÆÛ ¿À¹öÇÃ·Î¿ì ¿À·ù°¡ Á¸ÀçÇÑ´Ù.(CVE-2011-3222, CVE-2011-3223, CVE-2011-3247, CVE-2011-3249)
- Á¤ÀǵÇÁö ¾ÊÀº ¿À·ù´Â ƯÁ¤ ºñµð¿À ÆÄÀÏÀ» º¼ ¶§ ¸Þ¸ð¸® ¼Õ»óÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. (CVE-2011-3228)
- QuickTime ºñµð¿À ÆÄÀÏÀÇ ÆùÆ® Å×À̺íÀ» ó¸®ÇÒ ¶§ ºÎÈ£¿Í °ü·ÃµÈ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2011-3248)
- JPEG2000À¸·Î ÀÎÄÚµùµÈ ºñµð¿À ÆÄÀÏÀ» ó¸®ÇÒ ¶§ Á¤¼öÇü ¿À¹öÇÃ·Î¿ì ¿À·ù°¡ Á¸ÀçÇÑ´Ù. (CVE-2011-3250)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-11-295/
http://www.zerodayinitiative.com/advisories/ZDI-11-303/
http://www.zerodayinitiative.com/advisories/ZDI-11-311/
http://www.zerodayinitiative.com/advisories/ZDI-11-312/
http://www.zerodayinitiative.com/advisories/ZDI-11-313/
http://www.zerodayinitiative.com/advisories/ZDI-11-314/
http://www.zerodayinitiative.com/advisories/ZDI-11-315/
http://www.zerodayinitiative.com/advisories/ZDI-11-316/
http://support.apple.com/kb/HT5016

* ¿µÇâ¹Þ´Â Ç÷§Æû:
QuickTime versions prior to 7.7.1
Microsoft Windows Any version
ÇØ°áÃ¥ Apple À¥ »çÀÌÆ®ÀÎ http://www.apple.com/quicktime ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â QuickTimeÀÇ °¡Àå ÃֽŠ¹öÀü (7.7.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2011-3218,CVE-2011-3219,CVE-2011-3220,CVE-2011-3221,CVE-2011-3222,CVE-2011-3223,CVE-2011-3228,CVE-2011-3247,CVE-2011-3248 (CVE)
°ü·Ã URL 50068,50100,50101,50122,50127,50130,50131,50399,50400,50401,50403,50404 (SecurityFocus)
°ü·Ã URL (ISS)