English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26073
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í 'Exchange Server 2003¿¡ ÀÖ´Â ±ÇÇÑ »ó½Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(Q832759)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù.
Outlook Web Access (OWA)À» »ç¿ëÇÏ´Â Microsoft Exchange Server 2003Àº ¿ø°ÝÁöÀÇ ÀÎÁõµÈ OWA »ç¿ëÀÚ°¡ Ãë¾àÇÑ È£½ºÆ® »ó¿¡ ÀÖ´Â ´Ù¸¥ »ç¿ëÀÚµéÀÇ ¸ÞÀϹڽºµé¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¹®Á¦´Â ¾î¶² »ç¿ëÀÚ°¡ Exchange Server 2003°ú Microsoft Windows Server 2003 µÑ ´Ù°¡ ÀÛµ¿ÇÏ´Â ÄÄÇ»ÅÍ »ó¿¡ ÀÖ´Â Windows SharePoint Services 2.0À» ¼³Ä¡ÇÒ ¶§ ¹ß»ýÇÑ´Ù. ÀÌ °úÁ¤¿¡¼­ IIS (Internet Information Services)¿¡¼­ÀÇ Kerberos ÀÎÁõÀÌ »ç¿ë ºÒ°¡´ÉÇϵµ·Ï ¸¸µç´Ù. ÀÌ´Â OWA°¡ Exchange Server¿¡ ´ëÇØ À߸øµÈ Á¶ÀÛÀ» ÇÏ°Ô ÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms04-002.asp
http://www.securitytracker.com/alerts/2003/Nov/1008324.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Corporation Microsoft Exchange 2003
Microsoft Corporation Windows 2003 Server
ÇØ°áÃ¥ ´ÙÀ½ Microsoft º¸¾È °Ô½Ã¹° MS04-002¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms04-002.asp
°ü·Ã URL CVE-2003-0904 (CVE)
°ü·Ã URL 9118 (SecurityFocus)
°ü·Ã URL 13869 (ISS)