Ãë¾àÁ¡ID |
26277 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Windows DNS RPC ÀÎÅÍÆäÀ̽º¿¡ ÀÖ´Â ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡'¿¡ ´ëÇÑ hotfix(935966)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000 Server SP4, Server 2003 SP1, ±×¸®°í Server 2003 SP2´Â Domain Name System (DNS) ¼¹ö ¼ºñ½ºÀÇ RPC ¼ºñ½º¿¡ ÀÖ´Â ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. RPC °ü¸® ÀÎÅÍÆäÀ̽º·Î Àß Á¶ÀÛµÈ RPC ÆÐŶÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â SYSTEM ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ü¸® ÀÎÅÍÆäÀ̽º´Â ÀüÇüÀûÀ¸·Î 1024/tcp¿Í 5000/tcp »çÀÌÀÇ µ¿ÀûÀ¸·Î ÇÒ´çµÈ Æ÷Æ® »ó¿¡¼ ÀÛµ¿ÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº ¶ÇÇÑ SMB ¼ºñ½ºµé (139/tcp, 139/udp, 445/tcp, ±×¸®°í 445/udp)¿¡ ÀÇÇØ »ç¿ëµÇ´Â Æ÷Æ®µéÀ» ÅëÇؼµµ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx http://www.kb.cert.org/vuls/id/555920 http://www.us-cert.gov/cas/techalerts/TA07-103A.html http://www.securitytracker.com/id?1017910 http://secunia.com/advisories/24871 http://blogs.technet.com/msrc/archive/2007/04/12/microsoft-security-advisory-935964-posted.aspx
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows 2000 Server SP4 Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2003 SP2 |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-029¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(935966)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2007-1748 (CVE) |
°ü·Ã URL |
23470 (SecurityFocus) |
°ü·Ã URL |
33629 (ISS) |
|