English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 50052
À§Çèµµ 40
Æ÷Æ® 3689
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°ÝÀÇ iTunes´Â 11.0.3 ÀÌÀü ¹öÀüÀÌ¸ç ´ÙÀ½ÀÇ ÀáÀçÀûÀÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- ÀÎÁõ¿¡ °ü·ÃÇÑ ¿¡·¯°¡ Á¸ÀçÇÏ¿© ¹Î°¨ÇÑ Á¤º¸°¡ À¯ÃâµÉ ¼ö ÀÖÀ¸¸ç, ¿ÜºÎÀÇ ½Å·ÚµÇÁö ¸øÇÑ µ¥ÀÌÅÍ ¼Ò½º°¡ ¾îÇø®ÄÉÀ̼ǿ¡¼­ Çã¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ À̽´´Â ¿î¿µÃ¼Á¦¿Í ¹«°üÇÏ°Ô Á¸ÀçÇÑ´Ù. (CVE-2013-1014)

- °°ÀÌ Á¦°øµÇ´Â WebKit¿¡ ¿¡·¯°¡ Á¸ÀçÇØ ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Â memory corruptionÃë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. º¥´õ»ç´Â 'iTunes Store'¸¦ browseÇÒ ¶§ man-in-the-middle °ø°ÝÀÌ Çã¿ëµÉ ¼ö ÀÖ´Ù°í ¹àÇû´Ù. ÀÌ À̽´´Â Windows¿¡¸¸ ÇØ´çµÈ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.zerodayinitiative.com/advisories/ZDI-13-107/
http://www.zerodayinitiative.com/advisories/ZDI-13-108/
http://www.zerodayinitiative.com/advisories/ZDI-13-109/
http://support.apple.com/kb/HT5766
http://lists.apple.com/archives/security-announce/2013/May/msg00000.html
http://www.securityfocus.com/archive/1/526623/30/0/threaded

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apple Computer, Inc., iTunes 11.0.3 ÀÌÀüÀÇ ¹öÀüµé
ÇØ°áÃ¥ Apple ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.apple.com/itunes/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â iTunesÀÇ °¡Àå ÃֽŠ¹öÀü(11.0.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2012-2824,CVE-2012-2857,CVE-2012-3748,CVE-2012-5112,CVE-2013-0879,CVE-2013-0912,CVE-2013-0948,CVE-2013-0949,CVE-2013-0950,CVE-2013-0951 (CVE)
°ü·Ã URL 54203,54749,55867,56362,57576,57580,57581,57582,57584,57585 (SecurityFocus)
°ü·Ã URL (ISS)