English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26315
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Windows ¹Ìµð¾î ÆÄÀÏ Æ÷¸Ë¿¡ ÀÖ´Â Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(MS07-068, 941569 and 944275)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Windows 2000, XP, Server 2003, ±×¸®°í Vista¸¦ À§ÇÑ Microsoft Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, ±×¸®°í Windows Media Services 9.1Àº ASF ÆÄÀϵ鿡 ´ëÇÑ ºÎÀûÀýÇÑ ÆĽÌ(parsing)À¸·Î ÀÎÇÏ¿©, Èü ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¾î¶² »ç¿ëÀÚ¸¦ À¯µµÇÏ¿© Àß Á¶ÀÛµÈ ASF ÆÄÀÏÀ» ¾×¼¼½ºÇϵµ·Ï ÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx
http://www.kb.cert.org/vuls/id/319385

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Media Format Runtime 7.1
Microsoft Windows Media Format Runtime 9
Microsoft Windows Media Format Runtime 9.5
Microsoft Windows Media Format Runtime 9.5 x64 Edition
Microsoft Windows Media Format Runtime 11
Microsoft Windows Media Services 9.1
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Vista
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS07-068À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(KB941569 ȤÀº KB944275)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2007-0064 (CVE)
°ü·Ã URL 26776 (SecurityFocus)
°ü·Ã URL 33225,38711,38827,38828,38829,38830 (ISS)