English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22035
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS ¼­¹ö´Â 'IIS¸¦ À§ÇÑ ´©Àû ÆÐÄ¡' (Q319733)¿¡ ´ëÇÑ Hotfix°¡ ¼³Ä¡µÇÁö ¾ÊÀº °ÍÀ¸·Î ³ªÅ¸³­´Ù.
ÀÌ ÆÐÄ¡´Â À©µµ¿ìÁî NT 4.0 ¼­ºñ½ºÆÑ 6a ÀÌÈÄ IIS 4.0¿ëÀ¸·Î ¸±¸®ÁîµÈ ¸ðµç º¸¾È ÆÐÄ¡µé°ú IIS 5.0°ú 5.1¿ëÀ¸·Î ¸±¸®ÁîµÈ ¸ðµç º¸¾È ÆÐÄ¡µéÀÇ ±â´ÉÀ» Æ÷ÇÔÇÏ´Â ´©Àû ÆÐÄ¡ÀÌ´Ù. ÀÌÀü¿¡ ¸±¸®ÁîµÈ º¸¾È ÆÐÄ¡µé¿¡ Ãß°¡ÀûÀ¸·Î ÀÌ ÆÐÄ¡´Â ¶ÇÇÑ IIS 4.0, 5.0°ú 5.1¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â »õ·Ó°Ô ¹ß°ßµÈ ´ÙÀ½ º¸¾È Ãë¾àÁ¡µé¿¡ ´ëÇÑ FixµéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù.

o Chunked Encoding ¸ÞÄ¿´ÏÁò¿¡ ÀÖ´Â Buffer overrun: CVE-2002-0079
o ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®°¡ ÀÚü ¹ß°ßÇÑ º¯Á¾ Chunked Encoding buffer overrun: CVE-2002-0147
o HTTP Header handling¿¡ ÀÖ´Â Buffer Overrun: CVE-2002-0150
o ASP Server-Side Include Function¿¡ ÀÖ´Â Buffer Overrun: CVE-2002-0149
o HTR ISAPI extension¿¡ ÀÖ´Â Buffer Overrun: CVE-2002-0071
o URL ¿¡·¯ Çڵ帵¿¡ ÀÖ´Â Access violation: CVE-2002-0072
o FTP status ¿äûÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ: CVE-2002-0073
o IIS Help ÆÄÀÏ °Ë»ö ¼³ºñ¿¡ ÀÖ´Â Cross-site Scripting: CVE-2002-0074
o HTTP ¿¡·¯ ÆäÀÌÁö¿¡ ÀÖ´Â Cross-site Scripting: CVE-2002-0148
o Redirect Response ¸Þ¼¼Áö¿¡ ÀÖ´Â Cross-site Scripting: CVE-2002-0075

Ãë¾àÇÑ ¼ÒÇÁÆ®¿þ¾î:
¸¶ÀÌÅ©·Î¼ÒÆ÷Æ® Internet Information Server 4.0
¸¶ÀÌÅ©·Î¼ÒÆ÷Æ® Internet Information Services 5.0
¸¶ÀÌÅ©·Î¼ÒÆ÷Æ® Internet Information Services 5.1

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/8811.php
ÇØ°áÃ¥ 6.0 ¹öÀü ÀÌ»óÀÇ IIS·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-0644,CVE-2002-0645 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)