Ãë¾àÁ¡ID |
26289 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Microsoft XML Core Services¿¡ ÀÖ´Â ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡'¿¡ ´ëÇÑ hotfix(936227)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft XML Core Services (MSXML)´Â TextNode¿Í XMLDOM ¿ÀºêÁ§Æ®µé »óÀÇ substringData ¸Þ½îµå(method)¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Àß Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ Á¦ÀÛÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ǥÀû »ç¿ëÀÚ°¡ À¥»çÀÌÆ®¸¦ ¹æ¹®Çϰųª Àß Á¶ÀÛµÈ À̸ÞÀÏ ¸Þ½ÃÁö¸¦ º¼ °æ¿ì ÀáÀçÀûÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx http://www.securityfocus.com/archive/1/archive/1/476527/100/0/threaded http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576 http://www.zerodayinitiative.com/advisories/ZDI-07-048.html http://www.iss.net/threats/274.html http://www.kb.cert.org/vuls/id/361968 http://www.securitytracker.com/id?1018559 http://secunia.com/advisories/26447
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft XML Core Services 3.0 Microsoft XML Core Services 4.0 Microsoft XML Core Services 5.0 Microsoft XML Core Services 6.0 Microsoft Office 2003 SP2 Microsoft Office Sharepoint Server Microsoft Office Groove Server 2007 Microsoft Office System 2007 Microsoft Windows 2000 SP4 Microsoft Windows Server 2003 SP2 Microsoft Windows XP SP2 Microsoft Windows Vista |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-042¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(936227)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2007-2223 (CVE) |
°ü·Ã URL |
25301 (SecurityFocus) |
°ü·Ã URL |
35195 (ISS) |
|