English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26042
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛÀº ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® IIS¿¡ ´ëÇÑ °¡Àå ÃÖ½ÅÀÇ ´©Àû ÆÐÄ¡ ('Q11114'ÀÇ Hotfix)¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù. ÀÌÀü¿¡ ¸±¸®ÁîµÈ ¸ðµç º¸¾È ÆÐÄ¡µé¿¡ ´õÇÏ¿©, ÀÌ ÆÐÄ¡´Â ¶ÇÇÑ IIS 4.0, 5.0, ±×¸®°í 5.1¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â ´ÙÀ½°ú °°Àº »õ·Ó°Ô ¹ß°ßµÈ º¸¾È Ãë¾àÁ¡µé¿¡ ´ëÇÑ Fix¸¦ Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ ÆÐÄ¡°¡ ¾ø´Â IIS ¼­¹ö´Â ¿ø°Ý ȤÀº ·ÎÄ÷Π°ø°ÝÀÚ¿¡°Ô Ãë¾àÇÑ È£½ºÆ®»ó¿¡ SYSTEM ¼öÁØÀÇ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:

o Redirection Cross Site Scripting : CVE-2003-0223
o Server Side Include À¥ ÆäÀÌÁö ¹öÆÛ ¿À¹öÇ÷οì : CVE-2003-0224
o ASP Headers ¼­ºñ½º °ÅºÎ : CVE-2003-0225
o WebDAV ¼­ºñ½º °ÅºÎ : CVE-2003-0226

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms03-018.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Internet Information Server 4.0
Microsoft Internet Information Services 5.0
Microsoft Internet Information Services 5.1
ÇØ°áÃ¥ ¾Æ·¡ ¸®½ºÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.

IIS 4.0ÀÇ °æ¿ì:
http://microsoft.com/downloads/details.aspx?FamilyId=1DBC1914-98E9-4DED-ADBF-E9B374A1F79D&displaylang=en

IIS 5.0ÀÇ °æ¿ì:
http://microsoft.com/downloads/details.aspx?FamilyId=2F5D9852-4ADD-44F8-8715-AC3D7D7D94BF&displaylang=en

IIS 5.1ÀÇ °æ¿ì:
o 32-bit Edition:
http://microsoft.com/downloads/details.aspx?FamilyId=77CFE3EF-C5C5-401C-BC12-9F08154A5007&displaylang=en

o 64-bit Edition:
http://microsoft.com/downloads/details.aspx?FamilyId=86F4407E-B9BF-4490-9421-008407578D11&displaylang=en

* ¼³Ä¡ Ç÷§Æû:
o IIS 4.0 ÆÐÄ¡´Â Windows NT 4.0 Service Pack 6a°¡ ¼³Ä¡µÈ ½Ã½ºÅÛ¿¡ ¼³Ä¡µÉ ¼ö ÀÖ´Ù.
O IIS 5.0 ÆÐÄ¡´Â Windows 2000 Service Pack 2 ȤÀº Service Pack 3ÀÌ ¼³Ä¡µÈ ½Ã½ºÅÛ¿¡ ¼³Ä¡µÉ ¼ö ÀÖ´Ù.
O IIS 5.1 ÆÐÄ¡´Â Windows XP Professional Gold ±×¸®°í Service Pack 1ÀÌ ¼³Ä¡µÈ ½Ã½ºÅÛ¿¡ ¼³Ä¡µÉ ¼ö ÀÖ´Ù.

-- ȤÀº --

À©µµ¿ì Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ëÁßÀÎ À©µµ¿ìÁîÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2003-0223,CVE-2003-0224,CVE-2003-0225,CVE-2003-0226 (CVE)
°ü·Ã URL 7731,7735,7733 (SecurityFocus)
°ü·Ã URL (ISS)