Ãë¾àÁ¡ID |
26364 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â Microsoft Outlook Express¿Í Windows MailÀ» À§ÇÑ ´©Àû ¾÷µ¥ÀÌÆ®(MS08-048, 951066)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. Microsoft Outlook Express°ú Windows Mail´Â Microsoft Windows ¿î¿µÃ¼Á¦¿¡ žÀçµÇ´Â e-mail ¹× ´º½º±×·ì Ŭ¶óÀ̾ðÆ®ÀÌ´Ù. Microsoft Outlook Express 5.5 SP2 ±×¸®°í SP2±îÁöÀÇ 6, ±×¸®°í Windows MailÀº MHTML ÇÁ·ÎÅäÄÝ Ã³¸®±â°¡ MHTML ³»¿ëÀ» ¹ÝȯÇÒ ¶§ ÀÎÅÍ³Ý ÀͽºÇ÷η¯ µµ¸ÞÀÎ Á¦ÇѵéÀ» ¿ìȸÇÒ ¼ö ÀÖ´Â MHTML URL ¸®µð·º¼Ç(redirection)µéÀ» À߸ø Çؼ®ÇÔÀ¸·Î ÀÎÇÏ¿© Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÎÅÍ³Ý ÀͽºÇ÷η¯¸¦ ÀÌ¿ëÇÏ¿© ¾ÇÀÇÀûÀÎ À¥ ÆäÀÌÁö¸¦ Ç¥Àû »ç¿ëÀÚ°¡ ¹æ¹®Çϵµ·Ï À¯µµÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¸®µð·º¼Ç°ú °áÇÕÇÑ mhtml: URI¸¦ ÅëÇØ Á¢±Ù Á¦ÇÑ ÀåÄ¡µéÀ» ¿ìȸÇÏ¿© ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms08-048.mspx http://www.coresecurity.com/content/internet-explorer-zone-elevation http://secunia.com/advisories/31415
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Outlook Express 5.5 SP2 Microsoft Outlook Express 6.0 Microsoft Outlook Express 6.0 SP1 Microsoft Windows Mail Client Any version Microsoft Windows 2000 SP4 Microsoft Windows XP SP3 Microsoft Windows XP Pro x64 Edition SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 x64 Edition SP2 Microsoft Windows Vista SP1 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Server 2008 Microsoft Windows Server 2008 for x64-based Systems |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS08-048À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(951066)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms08-048.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2008-1448 (CVE) |
°ü·Ã URL |
30585 (SecurityFocus) |
°ü·Ã URL |
42679,42689 (ISS) |
|