English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26281
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â Microsoft Outlook Express¿Í Windows Mail¸¦ À§ÇÑ ´©Àû ¾÷µ¥ÀÌÆ®(MS07-034, 929123)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Outlook Express°ú Windows Mail´Â Microsoft Windows ¿î¿µÃ¼Á¦¿¡ žÀçµÇ´Â e-mail ¹× ´º½º±×·ì Ŭ¶óÀ̾ðÆ®ÀÌ´Ù. Outlook Express ¹öÀü 6À» ÀÛµ¿ÇÏ´Â Windows XP¿Í Windows Server 2003, ±×¸®°í Windows MailÀ» ÀÛµ¿ÇÏ´Â Windows Vista´Â ´ÙÀ½°ú °°ÀÌ Á¤º¸ ³ëÃâ Ãë¾àÁ¡°ú ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.

- URL Redirect Cross Domain Ãë¾àÁ¡ (CVE-2006-2111): Á¤º¸ ³ëÃâ
- Windows Mail UNC Navigation Request Ãë¾àÁ¡ (CVE-2007-1658): ¿ø°Ý ÄÚµå ½ÇÇà
- URL Parsing Cross Domain Ãë¾àÁ¡ (CVE-2007-2225): Á¤º¸ ³ëÃâ
- Content Disposition Parsing Cross Domain Ãë¾àÁ¡ (CVE-2007-2227): Á¤º¸ ³ëÃâ

À¥ »çÀÌÆ®¿¡ ¾ÇÀÇÀûÀÎ ÆÄÀÏÀ» È£½ºÆÃÇÏ¿© ÀáÀçÀûÀΠǥÀû »ç¿ëÀÚ°¡ ±× »çÀÌÆ®¸¦ ¹æ¹®Çϵµ·Ï À¯µµÇÔÀ¸·Î½á, ȤÀº email ÷ºÎ·Î ÀáÀçÀûÀΠǥÀû »ç¿ëÀÚ¿¡°Ô ±× ÆÄÀÏÀ» º¸³¿À¸·Î½á °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx
http://www.us-cert.gov/cas/techalerts/TA07-163A.html
http://www.kb.cert.org/vuls/id/682825
http://www.securitytracker.com/id?1018231
http://www.securitytracker.com/id?1018232
http://www.securitytracker.com/id?1018233
http://www.securitytracker.com/id?1018234
http://secunia.com/advisories/25639

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Outlook Express 6
Microsoft Windows Mail
Microsoft Windows XP Service Pack 2
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Vista
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-034¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(929123)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2006-2111,CVE-2007-1658,CVE-2007-2225,CVE-2007-2227 (CVE)
°ü·Ã URL 17717,23103,24392,24410 (SecurityFocus)
°ü·Ã URL 33167 (ISS)