English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26221
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft VBA¿¡ ÀÖ´Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS06-047, 921645)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. 'Microsoft Visual Basic for Applications' (VBA)´Â Ŭ¶óÀ̾ðÆ® µ¥½ºÅ©ÅéÀÇ ÆÐŰ¡µÈ ¾îÇø®ÄÉÀ̼ǵéÀ» °³¹ßÀ» À§ÇÑ ±×¸®°í Á¸ÀçÇÏ´Â µ¥ÀÌÅÍ¿Í ½Ã½ºÅ۵鿡 ±× ¾îÇø®ÄÉÀ̼ǵéÀ» ÅëÇÕÇϱâ À§ÇÑ °³¹ß ±â¼úÀÌ´Ù. Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, ±×¸®°í Works Suite 2004¿¡¼­ 2006±îÁöÀÇ ¹öÀüµé¿¡¼­ »ç¿ëµÇ´Â Microsoft VBA SDK 6.0¿¡¼­ 6.4±îÁöÀÇ ¹öÀüµéÀº ¹®¼­ µî·ÏÁ¤º¸(properties)¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿© ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. VBA Äڵ带 Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ Office ¹®¼­¸¦ Á¦ÀÛÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ǥÀû »ç¿ëÀÚ°¡ À¥»çÀÌÆ®¸¦ ¹æ¹®Çϰųª Àß Á¶ÀÛµÈ À̸ÞÀÏ ¸Þ½ÃÁö¸¦ º¼ °æ¿ì ÀáÀçÀûÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms06-047.mspx
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
http://www.kb.cert.org/vuls/id/159484
http://secunia.com/advisories/21408
http://securitytracker.com/id?1016656

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Access 2000 Runtime SP3
Microsoft Office 2000 SP3
Microsoft Office XP SP3
Microsoft Project 2000 SR1
Microsoft Project 2002 SP1
Microsoft Visio 2002 SP2
Microsoft Visual Basic for Applications SDK 6.0, 6.2, 6.3, 6.4
Microsoft Works Suite 2004, 2005, 2006
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS06-047À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(921645)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms06-047.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2006-3649 (CVE)
°ü·Ã URL 19414 (SecurityFocus)
°ü·Ã URL 28023,28024 (ISS)