English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26265
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft Office¿¡ ÀÖ´Â ¿ø°Ý ÄÚµå Ãë¾àÁ¡µé'¿¡ ´ëÇÑ hotfix(932554)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Office´Â ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µé·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù:

- PowerPoint ¾ÇÀÇÀûÀÎ ·¹ÄÚµå ¸Þ¸ð¸® Á¶ÀÛ Ãë¾àÁ¡ (CVE-2006-3877)
- Excel ¾ÇÀÇÀûÀÎ ·¹ÄÚµå Ãë¾àÁ¡ (CVE-2007-0671)

Àß Á¶ÀÛµÈ Office ÆÄÀÏÀ» Á¦ÀÛÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ǥÀû »ç¿ëÀÚ°¡ À¥»çÀÌÆ®¸¦ ¹æ¹®Çϰųª Àß Á¶ÀÛµÈ À̸ÞÀÏ ¸Þ½ÃÁö¸¦ º¼ °æ¿ì ÀáÀçÀûÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-015.mspx
http://www.kb.cert.org/vuls/id/613740
http://www.kb.cert.org/vuls/id/205948
http://vil.nai.com/vil/content/v_141393.htm
http://securitytracker.com/id?1017584
http://securitytracker.com/id?1017030
http://secunia.com/advisories/24008

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Visio 2002 SP2
Microsoft Visio 2002 SP1
Microsoft Project 2002 SP2 0
Microsoft Project 2002 SP1
Microsoft Project 2002 0
Microsoft Office XP SP1, SP2, SP3
Microsoft Office 2003 SP1, SP2
Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac
Apple Mac OS Any version
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-015¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(932554)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-015.mspx
°ü·Ã URL CVE-2006-3877,CVE-2007-0671 (CVE)
°ü·Ã URL 20325,22383 (SecurityFocus)
°ü·Ã URL 29234,29236,32178,32419 (ISS)