English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26300
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Windows Services for UNIX'¿¡ ÀÖ´Â ±ÇÇÑ »ó½Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS07-053, 939778)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000, XP, Server 2003, ±×¸®°í Vista¿¡ ÀÖ´Â UNIX 3.0°ú 3.5¸¦ À§ÇÑ Microsoft Windows ¼­ºñ½ºµé ±×¸®°í UNIX ±â¹Ý ¾îÇø®ÄÉÀ̼ǵéÀ» À§ÇÑ ºÎ¼Ó½Ã½ºÅÛÀº setuid ÀÌÁø(binary) ÆÄÀϵéÀ» À§ÇÑ Á¢¼Ó ½Å¿ëÁ¤º¸µé¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿©, ·ÎÄÃÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ°¡ Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡¼­ ±ÇÇÑÀ» »ó½Â½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ setuid ÀÌÁø ÆÄÀÏÀ» ½ÇÇà½ÃÅ´À¸·Î½á ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-053.mspx
http://www.us-cert.gov/cas/techalerts/TA07-254A.html
http://www.kb.cert.org/vuls/id/768440
http://securitytracker.com/id?1018678
http://secunia.com/advisories/26757

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Subsystem for UNIX-based Applications Any version
Microsoft Windows Services for UNIX 3.0
Microsoft Windows Services for UNIX 3.5
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64 Edition SP2
Microsoft Windows Vista
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-053À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(939778)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-053.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2007-3036 (CVE)
°ü·Ã URL 25620 (SecurityFocus)
°ü·Ã URL 36378,36381 (ISS)