Ãë¾àÁ¡ID |
28030 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç À©µµ¿ìÁî ½Ã½ºÅÛ¿¡ ÀÖ´Â MS Excel°ú Word¿¡´Â ´©Àû ÆÐÄ¡µéÀÌ Àû¿ëµÇ¾î ÀÖÁö ¾Ê´Ù. MS Excel°ú Word¿¡ ÀÖ´Â ´ÙÁß Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ »ç¿ëÀÚ ½Ã½ºÅÛ»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸ðµç Ãë¾àÁ¡µéÀº ¼º°øÀûÀÎ °ø°ÝÀ» À§ÇØ Á¤µµÀÇ Â÷ÀÌ´Â ÀÖÁö¸¸ »ç¿ëÀÚÀÇ ¹ÝÀÀÀ» ÇÊ¿ä·Î ÇÑ´Ù.
1. Excel ÀζóÀÎ Macro Ãë¾àÁ¡: CVE-2002-0616 À©µµ¿ìÁî¿ë Microsoft Excel 2000°ú 2002¿¡ ÀÖ´Â Macro º¸¾È¸ðµ¨Àº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô Excel Workbook ³»¿¡ ÀÖ´Â ¾î¶² ¿ÀºêÁ§Æ®¿¡ ÀζóÀÎ Macro¸¦ Ãß°¡ÇÔÀ¸·Î½á Äڵ带 ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
2. ÇÏÀÌÆÛ¸µÅ©µÈ Excel Workbook Macro ¿ìȸ Ãë¾àÁ¡: CVE-2002-0617 À©µµ¿ìÁî¿ë Microsoft Excel 2000°ú 2002¿¡ ÀÖ´Â Macro º¸¾È¸ðµ¨Àº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ÀÚµ¿¼öÇà ¸ÅÅ©·Î(autoexecute macro)¸¦ Æ÷ÇÔÇϰí ÀÖ´Â ¸ñÀûÁö WorkbookÀ» °¡¸£Å°´Â Ãâ¹ßÁö Workbook¿¡, ±×¸®±â Çü»ó(drawing shape)¿¡ ´ëÇÑ ÇÏÀÌÆÛ¸µÅ©¸¦ »ý¼ºÇÔÀ¸·Î½á Äڵ带 ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
3. Excel XSL ½ºÅ¸ÀϽ¬Æ®(Stylesheet) ½ºÅ©¸³Æ® ¼öÇà Ãë¾àÁ¡: CVE-2002-0618 À©µµ¿ìÁî¿ë Microsoft Excel 2000°ú 2002¿¡ ÀÖ´Â Macro º¸¾È¸ðµ¨Àº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô XSL ½ºÅ¸ÀϽ¬Æ®¸¦ Æ÷ÇÔÇϰí ÀÖ´Â Excel Workbook ³»¿¡ HTML ½ºÅ©¸³Æ®µéÀ» ³»Àå½ÃÅ´À¸·Î½á Local Computer Á¸¿¡ ÀÖ´Â Äڵ带 ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
4. MS00-071ÀÇ º¯Á¾, Word ¸ÞÀÏ º´ÇÕ Ãë¾àÁ¡: CVE-2002-0619 À©µµ¿ìÁî¿ë Microsoft Word 2002¿¡ ÀÖ´Â ¸ÞÀÏ º´ÇÕ ÅøÀº Microsoft Access°¡ ½Ã½ºÅÛ»ó¿¡ Á¸ÀçÇÒ °æ¿ì, ¿ø°ÝÁö °ø°ÝÀڵ鿡°Ô HTML Æ÷¸ËÀ¸·Î ÀúÀåµÈ ¸ÞÀÏ º´ÇÕ ¹®¼³»¿¡ ÀÖ´Â Visual Basic (VBA) ½ºÅ©¸³Æ®µéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* Note: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms02-031.asp http://marc.theaimsgroup.com/?l=ntbugtraq&m=102256054320377&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=102139136019862&w=2
* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î: Microsoft Excel 2000 for Windows Microsoft Office 2000 for Windows Microsoft Excel 2002 for Windows Microsoft Word 2002 for Windows Microsoft Office XP for Windows |
ÇØ°áÃ¥ |
´ÙÀ½ À¥»çÀÌÆ®µé·ÎºÎÅÍ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
Office Product Update »çÀÌÆ®: http://office.microsoft.com/productupdates/default.aspx
Windows¿ë Microsoft Excel 2000ÀÇ °æ¿ì: ÀÏ¹Ý Å¬¶óÀÌ¾ðÆ®¿ë ¼³Ä¡: http://office.microsoft.com/downloads/2000/exc0901.aspx
Windows¿ë Microsoft Excel 2002ÀÇ °æ¿ì: ÀÏ¹Ý Å¬¶óÀÌ¾ðÆ®¿ë ¼³Ä¡: http://office.microsoft.com/downloads/2002/exc1002.aspx
Microsoft Word 2002ÀÇ °æ¿ì: ÀÏ¹Ý Å¬¶óÀÌ¾ðÆ®¿ë ¼³Ä¡: http://office.microsoft.com/downloads/2002/wrd1004.aspx
* ÆÐÄ¡ ¼³Ä¡ °ËÁõ: À©µµ¿ìÁî¿ë Excel 2000: excel.exeÀÇ ¹öÀü ¹øÈ£°¡ 9.0.6508 ÀÎÁö¸¦ È®ÀÎÇÑ´Ù. À©µµ¿ìÁî¿ë Excel 2002: excel.exeÀÇ ¹öÀü ¹øÈ£°¡ 10.0.4109.0 ÀÎÁö¸¦ È®ÀÎÇÑ´Ù. À©µµ¿ìÁî¿ë Word 2002: Winword.exeÀÇ ¹öÀü ¹øÈ£°¡ 10.0.4109 ÀÎÁö¸¦ È®ÀÎÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-0616,CVE-2002-0617,CVE-2002-0618,CVE-2002-0619 (CVE) |
°ü·Ã URL |
4821 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|