Ãë¾àÁ¡ID |
26300 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Windows Services for UNIX'¿¡ ÀÖ´Â ±ÇÇÑ »ó½Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS07-053, 939778)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000, XP, Server 2003, ±×¸®°í Vista¿¡ ÀÖ´Â UNIX 3.0°ú 3.5¸¦ À§ÇÑ Microsoft Windows ¼ºñ½ºµé ±×¸®°í UNIX ±â¹Ý ¾îÇø®ÄÉÀ̼ǵéÀ» À§ÇÑ ºÎ¼Ó½Ã½ºÅÛÀº setuid ÀÌÁø(binary) ÆÄÀϵéÀ» À§ÇÑ Á¢¼Ó ½Å¿ëÁ¤º¸µé¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿©, ·ÎÄÃÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ°¡ Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡¼ ±ÇÇÑÀ» »ó½Â½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ setuid ÀÌÁø ÆÄÀÏÀ» ½ÇÇà½ÃÅ´À¸·Î½á ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms07-053.mspx http://www.us-cert.gov/cas/techalerts/TA07-254A.html http://www.kb.cert.org/vuls/id/768440 http://securitytracker.com/id?1018678 http://secunia.com/advisories/26757
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Subsystem for UNIX-based Applications Any version Microsoft Windows Services for UNIX 3.0 Microsoft Windows Services for UNIX 3.5 Microsoft Windows 2000 SP4 Microsoft Windows XP SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 x64 Edition SP2 Microsoft Windows Vista |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-053À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(939778)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms07-053.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2007-3036 (CVE) |
°ü·Ã URL |
25620 (SecurityFocus) |
°ü·Ã URL |
36378,36381 (ISS) |
|