English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26260
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft Malware º¸È£ ¿£Áø¿¡ ÀÖ´Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS07-010, 932135)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000 SP4, XP SP1°ú SP2, ±×¸®°í Server 2003 SP1, ±×¸®°í Vista´Â Àß Á¶ÀÛµÈ PDF ÆÄÀÏÀ» ó¸®ÇÒ ¶§ Microsoft Malware Protection Engine (mpengine.dll)¿¡ ÀÖ´Â Á¤¼öÇü ¿À¹öÇÃ·Î¿ì ¿À·ù·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. Ãë¾àÇÑ ¾îÇø®ÄÉÀ̼ǿ¡ ÀÇÇØ º¸È£µÇ°í ÀÖ´Â ½Ã½ºÅÛÀ¸·Î Àß Á¶ÀÛµÈ PDF ÆÄÀÏÀ» Æ÷ÇÔÇÑ emailÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-010.mspx
http://www.kb.cert.org/vuls/id/511577
http://www.securitytracker.com/id?1017636
http://secunia.com/advisories/24146

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Live OneCare Any version
Microsoft Antigen for Exchange Server 9.x
Microsoft Antigen for SMTP Server 9.x
Microsoft Forefront Security Exchange 10
Microsoft Forefront Security SharePoint 10
Microsoft Windows Defender Any version
Microsoft Windows Defender for Vista Any version
Microsoft Windows Defender x64 Edition Any version
Microsoft Windows Live Messenger Any version
Microsoft Windows Live Safety Center Any version
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2
Microsoft Windows Server 2003 SP1
Microsoft Windows Vista
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-010À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(932135)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-010.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2006-5270 (CVE)
°ü·Ã URL 22479 (SecurityFocus)
°ü·Ã URL 31127 (ISS)