English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25028
À§Çèµµ 40
Æ÷Æ® 1343
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç Microsoft SQL Server 2000Àº À߸øµÈ ·¹Áö½ºÆ®¸® Ű ÆÛ¹Ì¼Ç Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Microsoft SQL ¼­¹ö 2000 ±×¸®°í SQL Server Desktop Engine (MSDE) 2000Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© »ó½ÂµÈ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Microsoft SQL ¼­¹ö´Â ´ë°³ ¼³Ä¡ ½Ã¿¡ ½Ã½ºÅÛ °ü¸®Àڵ鿡 ÀÇÇØ Á¤ÀÇµÈ "service account" ±ÇÇÑÀ¸·Î ½ÇÇàµÈ´Ù. ÀÌ Á¤ÀÇ´Â SQL ¼­¹ö°¡ ·¹Áö½ºÆ®¸® Ű °ªÀÇ º¯°æÀÌ °¡´ÉÇÑ ÆÛ¹Ì¼ÇÀ» °¡Áö°í WindowsÀÇ ·¹Áö½ºÆ®¸®¿¡ ÀúÀåµÇ¾î ÀÖ´Ù. °á°úÀûÀ¸·Î "xp_regwrite"¶ó´Â Extended Stored Procedure¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» °¡Áø °ø°ÝÀÚµéÀº ±× ·¹Áö½ºÆ®¸® °ªÀ» º¯°æÇÏ¿© SQL ¼­¹ö°¡ "service account"·Î LocalSystemÀ¸·Î ÀÛµ¿Çϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.
¼­¹ö È£½ºÆ®¸¦ ¸®ºÎÆÃÇϰųª SQL ¼­ºñ½º¸¦ Àç½ÃÀÛÇϸé, SQL ¼­¹ö´Â Localsystem °èÁ¤ÀÇ ¿ÏÀüÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áö°í ÀÛµ¿ÇÏ°Ô µÈ´Ù. ÀÌ ´É·ÂÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿î¿µÃ¼Á¦ ±ÇÇÑÀ¸·Î ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Â SQL ÁúÀǹ®µéÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* ¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ´ÜÁö ´ë»ó SQL ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­, °ÅÁþ ¾ç¼º(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms02-034.asp
http://www.cert.org/advisories/CA-2002-22.html
http://www.kb.cert.org/vuls/id/796313

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft SQL Server 2000
Microsoft Desktop Engine (MSDE) 2000
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ °¡Àå ÃÖ½ÅÀÇ SQL ¼­¹ö 2000 ¼­ºñ½º ÆÑÀ» ±¸ÇÏ¿© ¼³Ä¡ÇÑ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;290211
°ü·Ã URL CVE-2002-0642 (CVE)
°ü·Ã URL 5205 (SecurityFocus)
°ü·Ã URL 9523 (ISS)