English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26124
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â SP3 ÀÌÀüÀÇ Microsoft Office 2000ÀÇ ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Microsoft Office 2000 SP2 ÀÌÇÏ´Â ·ÎÄà °ø°ÝÀÚ°¡ Á¢±Ù ±ÝÁöµÈ µå¶óÀ̹öµéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¹®Á¦´Â Á¤Ã¥(Policy)µéÀÌ Àû¿ëµÇ´Â ¹æ¹ý¿¡ ÀÖ´Ù. ±×·ì Á¤Ã¥(Group Policy)À» ¼³Á¤ÇÔÀ¸·Î½á µå¶óÀ̹ö¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦ÇÑÇÏ·Á ÇÒ ¶§, Á¢±Ù Á¦ÇÑÀº »ç¿ëÀڵ鿡 ´ëÇØ¼­¸¸ Àû¿ëµÇ°í ¼­ºñ½º³ª ÇÁ·Î±×·¥µé¿¡ ´ëÇØ¼­´Â Àû¿ëµÇÁö ¾Ê´Â´Ù. Ž»ö(browsing) ±â´ÉÀÌ Microsoft Excel ȤÀº Microsoft Word¿Í °°Àº ÇÁ·Î±×·¥À» ÅëÇÏ¿© ¼öÇàµÇ±â ¶§¹®¿¡ ±× ÇÁ·Î±×·¥Àº µå¶óÀ̹ö¸¦ º¼ ¼ö ÀÖ°Ô Çã°¡µÇ¾î ÀÖ´Ù. °á°úÀûÀ¸·Î Microsoft Office 2000 ÇÁ·Î±×·¥µéÀ» ÀÌ¿ëÇÏ¿© ·ÎÄà °ø°ÝÀÚ´Â Á¢±Ù ±ÝÁöµÈ µå¶óÀ̹öµéÀÇ ³»¿ëµéÀ» º¼ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®
http://support.microsoft.com/?id=302753
http://archives.neohapsis.com/archives/bugtraq/2005-02/0420.html
http://www.securiteam.com/windowsntfocus/5UP0M15EUW.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Office 2000 SP2 ÀÌÇÏ
Microsoft Windows 2000 Any version
ÇØ°áÃ¥ ´ÙÀ½ ÃֽŠOffice 2000 ¼­ºñ½º ÆÑ ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://support.microsoft.com/kb/276367 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ Microsoft Office 2000 ¼­ºñ½º ÆÑ(3 ȤÀº ÀÌÈÄ)À» ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-0545 (CVE)
°ü·Ã URL 12641 (SecurityFocus)
°ü·Ã URL 19461 (ISS)