English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26276
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft Exchange¿¡ ÀÖ´Â ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡µé'¿¡ ´ëÇÑ hotfix(931832)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. 2004³â 8¿ùÀÇ Exchange 2000 Post-Service Pack 3 Update Rollup(870540)À» °¡Áø Microsoft Exchange Server 2000, Microsoft Exchange Server 2003 SP1°ú SP2, ±×¸®°í Microsoft Exchange Server 2007Àº ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

- Outlook Web Access ½ºÅ©¸³Æ® ÁÖÀÔ Ãë¾àÁ¡ (CVE-2007-0220): Á¤º¸ ³ëÃâ
- Malformed iCal Ãë¾àÁ¡ (CVE-2007-0039): ¼­ºñ½º °ÅºÎ
- MIME µðÄÚµù Ãë¾àÁ¡ (CVE-2007-0213): ¿ø°Ý ÄÚµå ½ÇÇà
- IMAP Literal ó¸® Ãë¾àÁ¡ (CVE-2007-0221): ¼­ºñ½º °ÅºÎ

ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ÀÇÇØ ½ºÅ©¸³Æ® ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇϰųª ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Å³ª ȤÀº Ãë¾àÇÑ ½Ã½ºÅÛÀ» Àå¾ÇÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx
http://secunia.com/advisories/25183/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Exchange 2000 Server SP3
Microsoft Exchange Server 2003 SP1
Microsoft Exchange Server 2003 SP2
Microsoft Exchange Server 2007
Microsoft Windows 2000 Any version
Microsoft Windows 2003 Any version
Microsoft Windows Vista Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-026À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(931832)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2007-0220,CVE-2007-0039,CVE-2007-0213,CVE-2007-0221 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)