Áõ»ó:
ÀÎÅͳݿ¡ ¿¬°áÇÏ¿© µ¿¿µ»óÀ» º¸·Á°í Çϴµ¥ ¼Óµµ°¡ ´À¸®°Ô »ó¿µµÇ¾î º¸´Âµ¥ ¾î·Á¿òÀÌ ÀÖ½À´Ï´Ù.
¿øÀÎ:
1.¹Ìµð¾î Ç÷¹ÀÌ¾î ¹öÀüÀÌ ³·°Å³ª ¶Ç´Â 7.0 ÀÏ °æ¿ì ¿À·ù°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù
2.»ç¿ëÇϽô Àü¿ë¼± ÀÚüÀÇ ¼Óµµ¿¡ ¹®Á¦°¡ ÀÖ¾î¼ ¹ß»ýÇÒ ¼ö ÀÖ´Â ¹®Á¦ÀÔ´Ï´Ù.
ÇØ°á¹æ¹ý:
1. ¹Ìµð¾î Ç÷¹À̾ ³·Àº ¹öÀüÀ̶ó¸é ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵带 ÇϽʽÿÀ.»ç¿ëÇϽô ¹Ìµð¾î Ç÷¹ÀÌ¾î ¹öÀüÀÌ 6.0,6.4 ÀÌÇÏ ¹öÀüÀ̶ó¸é ¾Æ·¡ »çÀÌÆ®¿¡¼ ¾÷±×·¹À̵带 ¸ÕÀú ÇÏ¼Å¾ß µË´Ï´Ù."MS Windows Media Player" v6.4 Á¤½Ä ÇÑ±ÛÆÇ¼³Ä¡¸¦ ±ÇÀåÇÕ´Ï´Ù.ÆÄÀÏÀ̸§ : mediap64f.exe 3.4 Mbytehttp://file.simmani.com/view.php?dirid=20&num=4309À§ ¹Ù·Î °¡±â »çÀÌÆ®¿¡¼ Á÷Á¢ ´Ù¿î ¹ÞÀ¸½Å ÈÄ ¼³Ä¡ÇϽʽÿÀ.
´Ù¿î ¿Ï·á ÈÄ ¸¶¿ì½º·Î ´õºíŬ¸¯ ÇÏ½Ã¸é ¼³Ä¡µÉ °ÍÀÔ´Ï´Ù.¼³Ä¡ ¿Ï·á ÈÄ ½Ã½ºÅÛÀ» ÀçºÎÆÃ ÇϽʽÿÀ.¼³Ä¡ ¿Ï·á ÈÄ ¹Ìµð¾î Ç÷¹ÀÌ¾î º¸¾È ÆÐÄ¡¸¦ ÇÏ¼Å¾ß µË´Ï´ÙÀÎÅͳݿ¡¼ ½Ç½Ã°£ µ¿¿µ»óÀ» º¼ ¼ö ÀÖ´Â ÆÐÄ¡ ÆÄÀÏ ÀÔ´Ï´Ù.º¸¾È ÆÐÄ¡ "Windows Media Player 6.4 Security Patch"http://file.simmani.com/view.php?dirid=20&num=13612wmsu33995.exe 472 KbyteWindows Media Player 6.4 »ç¿ëÀÚ¸¦ À§ÇÑ º¸¾È ÆÐÄ¡ ÀÔ´Ï´Ù.
Microsoft Windows Media Player ¿¡ ÀÖ´Â ÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù. The ".ASX Buffer Overrun" vulnerability Windows Media Player ´Â ÀÎÅÍ³Ý »çÀÌÆ®¿¡¼ ½Ç½Ã°£ ¹æ¼ÛÀ» À§ÇÑ ½ºÆ®¸®¹Ö ¹Ìµð¾î¸¦ Àç»ýÇÒ ¼ö ÀÖ´Â Stream Redirector(.ASX) ÆÄÀÏÀ» Áö¿øÇÕ´Ï´Ù. ÀÌ .ASX ÆÄÀÏ¿¡ üũÇÏÁö ¸øÇÏ°Ô ÇÏ´Â Äڵ带 ³Ö¾î ¾ÇÀǸ¦ °¡Áø »ç¶÷ÀÌ À¥»çÀÌÆ®ÀÇ ÆÄÀÏÀ̳ª, ½ºÆ®¸®¹Ö ¹æ¼ÛÀ» º¸°Ô²û ÇÏ¿© »ç¿ëÀÚÀÇ ÄÄÇ»ÅÍ¿¡ ÀÚµ¿À¸·Î ¾î¶² µ¿ÀÛÀ» ÇÒ ¼ö ÀÖ´Â ¹®Á¦Á¡ÀÔ´Ï´Ù.
Windows Media Player 6.4, 7.0 ¸ðµÎ¿¡ ÇØ´çÇÕ´Ï´Ù°í°´´Ô²²¼ 7.0À» ¼³Ä¡ÇÑ °æ¿ì ½Ã¶ó¸é °°Àº ¹æ¹ýÀ¸·Î ÆÐÄ¡¸¦ ÇØÁÖ¼Å¾ß µË´Ï´Ù.º¸¾È ÆÐÄ¡ "Windows Media Player 7 Security Patch"http://file.simmani.com/view.php?dirid=20&num=13613wmsu34419.exe 1.4 Mbyte Microsoft Windows Media Player ¿¡ ÀÖ´Â µÎ °¡Áö º¸¾È Ãë¾à¼ºÀ» Á¦°ÅÇÒ ¼ö ÀÖ´Â ÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù.
¾Æ·¡´Â µÎ °¡Áö ¹®Á¦Á¡ÀÔ´Ï´Ù* The ".ASX Buffer Overrun" vulnerability Windows Media Player ´Â ÀÎÅÍ³Ý »çÀÌÆ®¿¡¼ ½Ç½Ã°£ ¹æ¼ÛÀ» À§ÇÑ ½ºÆ®¸®¹Ö ¹Ìµð¾î¸¦ Àç»ýÇÒ ¼ö ÀÖ´Â Stream Redirector(.ASX) ÆÄÀÏÀ» Áö¿øÇÕ´Ï´Ù.
ÀÌ .ASX ÆÄÀÏ¿¡ üũÇÏÁö ¸øÇÏ°Ô ÇÏ´Â Äڵ带 ³Ö¾î ¾ÇÀǸ¦ °¡Áø »ç¶÷ÀÌ À¥»çÀÌÆ®ÀÇ ÆÄÀÏÀ̳ª, ½ºÆ®¸®¹Ö ¹æ¼ÛÀ» º¸°Ô²û ÇÏ¿© »ç¿ëÀÚÀÇ ÄÄÇ»ÅÍ¿¡ ÀÚµ¿À¸·Î ¾î¶² µ¿ÀÛÀ» ÇÒ ¼ö ÀÖ´Â ¹®Á¦Á¡ÀÔ´Ï´Ù.
Windows Media Player 6.4, 7.0 ¸ðµÎ¿¡ ÇØ´çÇÕ´Ï´Ù.
* The ¡°.WMS Script Execution¡± vulnerability * Windows Media Player 7 Àº Skin ±â´ÉÀ» ä¿ëÇÏ¿© µè´Â °ÍÀ» ³Ñ¾î º¸´Â Áñ°Å¿ò±îÁö ÁÙ ¼ö ÀÖµµ·Ï ÇÏ¿´½À´Ï´Ù. ÇÏÁö¸¸ Skin ±â´É¿¡ ¾ÇÀǸ¦ °¡Áø »ç¶÷ÀÌ Æ¯Á¤ Script ¸¦ Æ÷ÇÔ½Ã۰í ÀÌ Skin À» ¼±ÅÃÇÒ °æ¿ì, »ç¿ëÀÚ°¡ ƯÁ¤ »çÀÌÆ®¿¡ °¬À» ¶§ ActiveX ÄÁÆ®·ÑÀ» ÀÌ¿ëÇÏ¿© »ç¿ëÀÚÀÇ ÄÄÇ»ÅÍ¿¡¼ ÀÚµ¿À¸·Î ¾î¶² µ¿ÀÛÀ» ÇÒ ¼ö ÀÖ°Ô ÇÏ´Â ¹®Á¦Á¡ÀÔ´Ï´Ù.
2. »ç¿ëÇϽô Àü¿ë¼± ÀÚüÀÇ ¼Óµµ¿¡ ¹®Á¦°¡ ÀÖ¾î¼ ¹ß»ýÇÒ ¼ö ÀÖ´Â ¹®Á¦ÀÔ´Ï´Ù.»ç¿ëÇϽô ÀÎÅÍ³Ý Àü¿ë¼±ÀÇ ¼Óµµ¿¡ ¹®Á¦°¡ ÀÖ´Â °æ¿ì ½Ç½Ã°£ µ¿¿µ»óÀ» º¼¶§ ȸéÀÌ ³ª¿À´Ù ¸ØÃ߰ųª óÀ½ºÎÅÍ È¸éÀÌ °Ë°Ô ³ª¿À´Â°æ¿ì°¡ ÀÖ½À´Ï´Ù.
½ÃÀÛ¹öư-½ÇÇà¿¡¼ winipcfg ÀÔ·Â ÈÄ ¿£ÅÍ Çϼż ÀÚ¼¼È÷¸¦ ´©¸£½Ã¸é ¿¹¸¦ µé¾î dns ÁÖ¼Ò°¡ ³ª¿É´Ï´Ù dnsÁÖ¼Ò°¡ 123.456.78.9¶ó¸é ½ÃÀÛ¹öư-½ÇÇà¿¡¼ ping 123.456.78.9 -t ÀÔ·Â ÈÄ ¿£Å͸¦ ÇÕ´Ï´Ù. ±×·¯¸é ¼ýÀÚ°¡ Reply from 123.456.78.9 bytes=32 time=10ms TTl=123 ÀÌ·¸°Ô ³ª¿É´Ï´Ù. ¿©±â¼ 10msÀÇ ¼ýÀÚ°¡ ÀûÀ»¼ö·Ï ÁÁ½À´Ï´Ù. 10ms ¿¡¼ 30ms »çÀÌ¿¡ ¸¹Àº º¯È°¡ ¾øÀÌ ³ª¿Â´Ù¸é ¾ÈÁ¤ÀûÀÔ´Ï´Ù.Reply from 123.456.78.9 bytes=32 time=10ms TTl=123Reply from 123.456.78.9 bytes=32 time=11ms TTl=123Reply from 123.456.78.9 bytes=32 time=10ms TTl=123Reply from 123.456.78.9 bytes=32 time=13ms TTl=12330ms ¿¡¼ 1~200ms ¿¡¼ º¯È°¡ ¸¹Àº »óÅ·Π³ª¿Â´Ù¸é ¼Óµµ°¡ ´À¸®°í ȸ¼±ÀÌ ºÒ¾ÈÁ¤ÇÑ °ÍÀÔ´Ï´Ù. Reply from 123.456.78.9 bytes=32 time=010ms TTl=123Reply from 123.456.78.9 bytes=32 time=120ms TTl=123Reply from 123.456.78.9 bytes=32 time=100ms TTl=123Reply from 123.456.78.9 bytes=32 time=110ms TTl=123µû¶ó¼ ÇØ°á¹æ¹ýÀº °¡ÀÔÇϽŠÀü¿ë¼± ȸ»ç·Î ¹®ÀǸ¦ Çϼż ȸ¼±Á¡°ËÀ» ¹®ÀÇ ¹× Á¢¼öÇϽøé Á÷¿øÀÌ ÃâÀå ³ª¿Í¼ Á¡°ËÀ» ÇØµå¸± °ÍÀÔ´Ï´Ù.
Ãâó:´ÙÀ½Ä«Æä-¿ïµåPCÁ¤ºñ Àü¹® Çпø