Ãë¾àÁ¡ID |
26259 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft Data Access ±¸¼º¿ä¼Òµé¿¡ ÀÖ´Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS07-009, 927779)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000 SP4, XP SP1°ú SP2, ±×¸®°í Server 2003 SP1Àº ADODB.Connection 2.7 and 2.8 ActiveX ÄÁÆ®·Ñ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϰųª ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ HTML ¹®¼(¿¹¸¦µé¾î, À¥ ÆäÀÌÁö³ª HTML email ¸Þ½ÃÁö ȤÀº ÷ºÎ)¸¦ ¾î¶² »ç¿ëÀÚ°¡ º¸µµ·Ï À¯µµÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼ºñ½º °ÅºÎ(ÀÎÅÍ³Ý ÀͽºÇ÷η¯ Å©·¡½¬)¸¦ ÀÏÀ¸Å°°Å³ª ȤÀº ÇØ´ç »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx http://securitytracker.com/alerts/2006/Oct/1017127.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Data Access Components (MDAC) 2.5 SP3 Microsoft Data Access Components (MDAC) 2.7 SP1 Microsoft Data Access Components (MDAC) 2.8 SP1 Microsoft Windows 2000 SP4 Microsoft Windows XP SP2 Microsoft Windows Server 2003 SP1 |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-009¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(927779)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2006-5559 (CVE) |
°ü·Ã URL |
20704 (SecurityFocus) |
°ü·Ã URL |
29837 (ISS) |
|