Ãë¾àÁ¡ID |
26221 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft VBA¿¡ ÀÖ´Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS06-047, 921645)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. 'Microsoft Visual Basic for Applications' (VBA)´Â Ŭ¶óÀ̾ðÆ® µ¥½ºÅ©ÅéÀÇ ÆÐŰ¡µÈ ¾îÇø®ÄÉÀ̼ǵéÀ» °³¹ßÀ» À§ÇÑ ±×¸®°í Á¸ÀçÇÏ´Â µ¥ÀÌÅÍ¿Í ½Ã½ºÅ۵鿡 ±× ¾îÇø®ÄÉÀ̼ǵéÀ» ÅëÇÕÇϱâ À§ÇÑ °³¹ß ±â¼úÀÌ´Ù. Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, ±×¸®°í Works Suite 2004¿¡¼ 2006±îÁöÀÇ ¹öÀüµé¿¡¼ »ç¿ëµÇ´Â Microsoft VBA SDK 6.0¿¡¼ 6.4±îÁöÀÇ ¹öÀüµéÀº ¹®¼ µî·ÏÁ¤º¸(properties)¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿© ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. VBA Äڵ带 Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ Office ¹®¼¸¦ Á¦ÀÛÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ǥÀû »ç¿ëÀÚ°¡ À¥»çÀÌÆ®¸¦ ¹æ¹®Çϰųª Àß Á¶ÀÛµÈ À̸ÞÀÏ ¸Þ½ÃÁö¸¦ º¼ °æ¿ì ÀáÀçÀûÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms06-047.mspx http://www.us-cert.gov/cas/techalerts/TA06-220A.html http://www.kb.cert.org/vuls/id/159484 http://secunia.com/advisories/21408 http://securitytracker.com/id?1016656
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Access 2000 Runtime SP3 Microsoft Office 2000 SP3 Microsoft Office XP SP3 Microsoft Project 2000 SR1 Microsoft Project 2002 SP1 Microsoft Visio 2002 SP2 Microsoft Visual Basic for Applications SDK 6.0, 6.2, 6.3, 6.4 Microsoft Works Suite 2004, 2005, 2006 Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS06-047À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(921645)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms06-047.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2006-3649 (CVE) |
°ü·Ã URL |
19414 (SecurityFocus) |
°ü·Ã URL |
28023,28024 (ISS) |
|