English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26364
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â Microsoft Outlook Express¿Í Windows MailÀ» À§ÇÑ ´©Àû ¾÷µ¥ÀÌÆ®(MS08-048, 951066)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Outlook Express°ú Windows Mail´Â Microsoft Windows ¿î¿µÃ¼Á¦¿¡ žÀçµÇ´Â e-mail ¹× ´º½º±×·ì Ŭ¶óÀ̾ðÆ®ÀÌ´Ù. Microsoft Outlook Express 5.5 SP2 ±×¸®°í SP2±îÁöÀÇ 6, ±×¸®°í Windows MailÀº MHTML ÇÁ·ÎÅäÄÝ Ã³¸®±â°¡ MHTML ³»¿ëÀ» ¹ÝȯÇÒ ¶§ ÀÎÅÍ³Ý ÀͽºÇ÷η¯ µµ¸ÞÀÎ Á¦ÇѵéÀ» ¿ìȸÇÒ ¼ö ÀÖ´Â MHTML URL ¸®µð·º¼Ç(redirection)µéÀ» À߸ø Çؼ®ÇÔÀ¸·Î ÀÎÇÏ¿© Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÎÅÍ³Ý ÀͽºÇ÷η¯¸¦ ÀÌ¿ëÇÏ¿© ¾ÇÀÇÀûÀÎ À¥ ÆäÀÌÁö¸¦ Ç¥Àû »ç¿ëÀÚ°¡ ¹æ¹®Çϵµ·Ï À¯µµÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¸®µð·º¼Ç°ú °áÇÕÇÑ mhtml: URI¸¦ ÅëÇØ Á¢±Ù Á¦ÇÑ ÀåÄ¡µéÀ» ¿ìȸÇÏ¿© ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms08-048.mspx
http://www.coresecurity.com/content/internet-explorer-zone-elevation
http://secunia.com/advisories/31415

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Outlook Express 5.5 SP2
Microsoft Outlook Express 6.0
Microsoft Outlook Express 6.0 SP1
Microsoft Windows Mail Client Any version
Microsoft Windows 2000 SP4
Microsoft Windows XP SP3
Microsoft Windows XP Pro x64 Edition SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 x64 Edition SP2
Microsoft Windows Vista SP1
Microsoft Windows Vista x64 Edition SP1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 for x64-based Systems
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS08-048À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(951066)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms08-048.mspx

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2008-1448 (CVE)
°ü·Ã URL 30585 (SecurityFocus)
°ü·Ã URL 42679,42689 (ISS)