English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26145
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Telnet Ŭ¶óÀ̾ðÆ®¿¡ ÀÖ´Â Á¤º¸ ³ëÃâ Ãë¾àÁ¡'¿¡ ´ëÇÑ hotfix(KB896428)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows XP, Windows Server 2003, ±×¸®°í Windows Services for UNIX¸¦ À§ÇÑ Telnet Ŭ¶óÀ̾ðÆ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ SEND ENV_USERVAR ¸í·É¿¡ ÀÖ´Â NEW-ENVIRON ¿É¼ÇÀ» °æÀ¯ÇÏ¿© ¹Î°¨ÇÑ È¯°æ º¯¼öµéÀ» ÀÐ¾î °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ Telnet ¼­¹ö¿¡ ¿¬°áÀ» ¸Î°í ÀÖ´Â »ç¿ëÀÚµéÀÇ ¼¼¼Ç º¯¼öµéÀ» ¿ø°ÝÀ¸·Î ÀÐ¾î °¥ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms05-033.mspx
http://www.kb.cert.org/vuls/id/800829
http://secunia.com/advisories/15690/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Services for UNIX 3.5 for Windows 2000
Microsoft Windows Services for UNIX 3.0 for Windows 2000
Microsoft Windows Services for UNIX 2.2 for Windows 2000
Microsoft Windows XP Service Pack 2
Microsoft Windows Server 2003 Service Pack 1
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS05-033À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(KB896428)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms05-033.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2005-1205 (CVE)
°ü·Ã URL 13940 (SecurityFocus)
°ü·Ã URL 20813 (ISS)