English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25026
À§Çèµµ 40
Æ÷Æ® 1433
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í Microsoft SQL Server¿¡ ´ëÇÑ ´©Àû ÆÐÄ¡ KB815495°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù.
ÀÌ ´©Àû ÆÐÄ¡´Â SQL Server 7.0, SQL Server 2000, MSDE 1.0, ±×¸®°í MSDE 2000¿¡ ´ëÇØ ÀÌÀü¿¡ ¸±¸®ÁîµÈ ¸ðµç ÆÐÄ¡µéÀ» Æ÷ÇÔÇÑ´Ù. ¿©±â¿¡ ´õÇÏ¿© ´ÙÀ½ ¼¼ °¡ÁöÀÇ »õ·Ó°Ô ¹ß°ßµÈ Ãë¾àÁ¡µéÀ» Á¦°ÅÇØ ÁØ´Ù:

- Named Pipe °¡·Îä±â (±ÇÇÑ »ó½Â)
- Named Pipe ¼­ºñ½º °ÅºÎ
- SQL Server Buffer Overrun (·ÎÄÿ¡ ÇÑÁ¤)

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms03-031.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft SQL Server 2000 64 bit (all editions)
Microsoft SQL Server 2000 (all editions) SP3
Microsoft SQL Server 2000 (all editions) SP3a
Microsoft SQL Server 7.0 Service Pack 4
Microsoft SQL Server 2000 Desktop Engine (MSDE) SP3
Microsoft Data Engine (MSDE) 1.0
Microsoft Data Engine (MSDE) 1.0 SP4
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-031À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms03-031.asp

Microsoft SQL Server 7.0ÀÇ °æ¿ì:
http://microsoft.com/downloads/details.aspx?FamilyId=FE5B0892-A5C9-44C2-9B42-0D291E9C1636&displaylang=en
Microsoft SQL 2000 32-bit EditionÀÇ °æ¿ì:
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C5-ADD3-B8C99618E68D&displaylang=en
Microsoft SQL 2000 64-bit EditionÀÇ °æ¿ì:
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E86-8F2E-CB1BD3A6A44B&displaylang=en

-- ȤÀº --

À©µµ¿ìÁî Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ëÁßÀÎ À©µµ¿ìÁîÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2003-0230,CVE-2003-0231,CVE-2003-0232 (CVE)
°ü·Ã URL 8261 (SecurityFocus)
°ü·Ã URL (ISS)