Ãë¾àÁ¡ID |
26540 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â ¡®SChannelÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡¡¯ ¿¡ ´ëÇÑ hotfix(MS10-085, 2207566)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â WindowsÀÇ Secure Channel(SChannel) º¸¾È ÆÐÅ°Áö¿¡¼ ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù. SSL(Secure Sockets Layer) »ç¿ëÀÌ °¡´ÉÇÑ À¥ »çÀÌÆ®¸¦ È£½ºÆÃÇÏ´Â ¿µÇâÀ» ¹Þ´Â IIS(ÀÎÅÍ³Ý Á¤º¸ ¼ºñ½º) ¼¹ö°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ ÆÐŶ ¸Þ½ÃÁö¸¦ ¹ÞÀº °æ¿ì ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ ¼ºñ½º °ÅºÎ°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ±âº»ÀûÀ¸·Î IIS´Â SSL À¥ »çÀÌÆ®¸¦ È£½ºÆÃÇϵµ·Ï ±¸¼ºµÇ¾î ÀÖÁö ¾Ê½À´Ï´Ù. º¸¾È ¾÷µ¥ÀÌÆ®´Â IIS¿¡¼ Ŭ¶óÀ̾ðÆ® ÀÎÁõ¼ ¿äûÀ» ó¸®ÇÏ´Â ¹æ½ÄÀ» º¯°æÇÏ¿© ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/Bulletin/MS10-085.mspx
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Windows Server 2003 SP2 Windows Vista SP1 and SP2 Windows Vista x86 SP1 and SP2 Windows Server 2008 and SP2 Windows Server x64 2008 and SP2 Windows Server for Itanium-based Windows 7 Windows 7 x64 Windows Server x64 2008 R2 Windows Server 2008 R2 for Itanium-based |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS10-085¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(2207566)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms10-085.mspx |
°ü·Ã URL |
CVE-2009-3229 (CVE) |
°ü·Ã URL |
43780 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|