English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26212
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'ASP¸¦ »ç¿ëÇÏ´Â IISÀÇ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(KB917537)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000, Windows XP, ±×¸®°í Windows Server 2003Àº ºñÁ¤»óÀûÀÎ Active Server Page(ASP)¸¦ ó¸®ÇÒ ¶§ÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡Àº ¾ÇÀÇÀûÀÎ "ASP" ÆäÀÌÁö¸¦ ¾÷·ÎµåÇÒ ¼ö ÀÖ´Â °ø°ÝÀÚ¿¡ ÀÇÇØ µµ¿ëµÉ ¼ö ÀÖÀ¸¸ç À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx
http://www.kb.cert.org/vuls/id/395588
http://www.us-cert.gov/cas/techalerts/TA06-192A.html
http://secunia.com/advisories/21006
http://securitytracker.com/id?1016466

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Internet Information Services (IIS) 6.0
Microsoft Internet Information Services (IIS) 5.1
Microsoft Internet Information Services (IIS) 5.0
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2
Microsoft Windows Server 2003
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS06-034¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(KB917537)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2006-0026 (CVE)
°ü·Ã URL 18858 (SecurityFocus)
°ü·Ã URL 26796,26883 (ISS)