Ãë¾àÁ¡ID |
26281 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â Microsoft Outlook Express¿Í Windows Mail¸¦ À§ÇÑ ´©Àû ¾÷µ¥ÀÌÆ®(MS07-034, 929123)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Outlook Express°ú Windows Mail´Â Microsoft Windows ¿î¿µÃ¼Á¦¿¡ žÀçµÇ´Â e-mail ¹× ´º½º±×·ì Ŭ¶óÀ̾ðÆ®ÀÌ´Ù. Outlook Express ¹öÀü 6À» ÀÛµ¿ÇÏ´Â Windows XP¿Í Windows Server 2003, ±×¸®°í Windows MailÀ» ÀÛµ¿ÇÏ´Â Windows Vista´Â ´ÙÀ½°ú °°ÀÌ Á¤º¸ ³ëÃâ Ãë¾àÁ¡°ú ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
- URL Redirect Cross Domain Ãë¾àÁ¡ (CVE-2006-2111): Á¤º¸ ³ëÃâ - Windows Mail UNC Navigation Request Ãë¾àÁ¡ (CVE-2007-1658): ¿ø°Ý ÄÚµå ½ÇÇà - URL Parsing Cross Domain Ãë¾àÁ¡ (CVE-2007-2225): Á¤º¸ ³ëÃâ - Content Disposition Parsing Cross Domain Ãë¾àÁ¡ (CVE-2007-2227): Á¤º¸ ³ëÃâ
À¥ »çÀÌÆ®¿¡ ¾ÇÀÇÀûÀÎ ÆÄÀÏÀ» È£½ºÆÃÇÏ¿© ÀáÀçÀûÀΠǥÀû »ç¿ëÀÚ°¡ ±× »çÀÌÆ®¸¦ ¹æ¹®Çϵµ·Ï À¯µµÇÔÀ¸·Î½á, ȤÀº email ÷ºÎ·Î ÀáÀçÀûÀΠǥÀû »ç¿ëÀÚ¿¡°Ô ±× ÆÄÀÏÀ» º¸³¿À¸·Î½á °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx http://www.us-cert.gov/cas/techalerts/TA07-163A.html http://www.kb.cert.org/vuls/id/682825 http://www.securitytracker.com/id?1018231 http://www.securitytracker.com/id?1018232 http://www.securitytracker.com/id?1018233 http://www.securitytracker.com/id?1018234 http://secunia.com/advisories/25639
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Outlook Express 6 Microsoft Windows Mail Microsoft Windows XP Service Pack 2 Microsoft Windows Server 2003 Service Pack 1 Microsoft Windows Server 2003 Service Pack 2 Microsoft Windows Vista |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-034¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(929123)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2006-2111,CVE-2007-1658,CVE-2007-2225,CVE-2007-2227 (CVE) |
°ü·Ã URL |
17717,23103,24392,24410 (SecurityFocus) |
°ü·Ã URL |
33167 (ISS) |
|