English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26238
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft Office¿¡ ÀÖ´Â ¿ø°Ý ÄÚµå Ãë¾àÁ¡µé'¿¡ ´ëÇÑ hotfix(922581)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Office´Â ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µé·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù:

- Office ºÎÀûÀýÇÑ ¸Þ¸ð¸® Á¢±Ù Ãë¾àÁ¡ (CVE-2006-3434)
- Office ºñÁ¤»óÀûÀÎ Chart Record Ãë¾àÁ¡ (CVE-2006-3650)
- Office ºñÁ¤»óÀûÀÎ ·¹ÄÚµå ¸Þ¸ð¸® Ãë¾àÁ¡ (CVE-2006-3864)
- Microsoft Office Smart Tag Parsing Ãë¾àÁ¡ (CVE-2006-3868)

Àß Á¶ÀÛµÈ Office ÆÄÀÏÀ» Á¦ÀÛÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ǥÀû »ç¿ëÀÚ°¡ À¥»çÀÌÆ®¸¦ ¹æ¹®Çϰųª Àß Á¶ÀÛµÈ À̸ÞÀÏ ¸Þ½ÃÁö¸¦ º¼ °æ¿ì ÀáÀçÀûÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms06-058.mspx
http://www.kb.cert.org/vuls/id/187028
http://www.kb.cert.org/vuls/id/205948
http://www.kb.cert.org/vuls/id/938196
http://www.kb.cert.org/vuls/id/231204
http://www.zerodayinitiative.com/advisories/ZDI-06-032.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Visio 2002 SP2
Microsoft Visio 2002 SP1
Microsoft Project 2002 SP2 0
Microsoft Project 2002 SP1
Microsoft Project 2002 0
Microsoft Office XP SP1, SP2, SP3
Microsoft Office 2003 SP1, SP2
Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac
Apple Mac OS Any version
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS06-062¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(922581)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms06-062.mspx
°ü·Ã URL CVE-2006-3434,CVE-2006-3650,CVE-2006-3864,CVE-2006-3868 (CVE)
°ü·Ã URL 20320 (SecurityFocus)
°ü·Ã URL 29209,29212,29213,29214,29216 (ISS)