Ãë¾àÁ¡ID |
28053 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'VBA(Visual Basic for Applications)ÀÇ °áÇÔÀ¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(822715)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. MS VBA´Â Ŭ¶óÀÌ¾ðÆ® µ¥½ºÅ©Åé ÆÐŰÁö ÀÀ¿ë ÇÁ·Î±×·¥À» °³¹ßÇϰí À̵éÀ» ±âÁ¸ µ¥ÀÌÅÍ ¹× ½Ã½ºÅÛ°ú ÅëÇÕÇÏ´Â °³¹ß ±â¼ú·Î½á, MS ¿ÀÇǽº Á¦Ç°¿¡ Æ÷ÇÔµÇ¾î Æ¯Á¤ ±â´ÉÀ» ¼öÇàÇϱâ À§ÇØ È°¿ëµÈ´Ù. VBA 5.0, 6,0, 6,2 ¶Ç´Â 6.3 ¹öÀüÀÇ °æ¿ì, ÀÀ¿ëÇÁ·Î±×·¥¿¡¼ ¹®¼°¡ ¿¸± ¶§ VBA¿¡ Àü´ÞµÇ´Â ÀϺΠ¹®¼ÀÇ ¼Ó¼º(properties)ÀÌ ¿Ã¹Ù¸£°Ô °Ë»çµÇÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§Çؼ, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¿öµå ¹®¼, ¿¢¼¿ ½ºÇÁ·¹µå ½¬Æ®, ÆÄ¿ö Æ÷ÀÎÆ® ÇÁ¸®Á¨Å×À̼ǰú °°ÀÌ VBA¸¦ Áö¿øÇÏ´Â Àß Á¶ÀÛµÈ ¹®¼¸¦ ¸¸µé°í, »ç¿ëÀÚ°¡ ÀÌ ¹®¼¸¦ ¿µµ·Ï À¯µµÇÑ´Ù. ÀÏ´Ü ¾ÇÀÇÀûÀÎ ¹®¼°¡ ¿¸®°Ô µÇ¸é, ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ°í ¿ø°ÝÁö °ø°ÝÀÚµéÀº ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÑ »ç¿ëÀÚ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/MS03-037.asp http://archives.neohapsis.com/archives/bugtraq/2003-09/0037.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Visual Basic for Applications SDK 5.0 , 6,0, 6.2, 6.3 ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¸¦ Æ÷ÇÔÇÏ´Â Á¦Ç°: Microsoft Access 97, 2000, 2002 Microsoft Excel 97, 2000, 2002 Microsoft PowerPoint 97, 2000, 2002 Microsoft Project 2000, 2002 Microsoft Publisher 2002 Microsoft Visio 2000, 2002 Microsoft Word 97, 98(J), 2000, 2002 Microsoft Works Suite 2001, 2002, 2003 Microsoft Business Solutions Great Plains 7.5 Microsoft Business Solutions Dynamics 6.0, 7.0 Microsoft Business Solutions eEnterprise 6.0, 7.0 Microsoft Business Solutions Solomon 4.5, 5.0, 5,5 |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-037¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/MS03-037.asp
1. ´ÙÀ½ÀÇ ÆäÀÌÁö¸¦ ¿¬´Ù: MS Office 2000ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=E2CCE199-9C4A-4EEC-A3EC-9F738017F275&displaylang=en http://www.microsoft.com/office/ork/xp/journ/o2k0901a.htm (°ü¸®ÀÚ ¾÷µ¥ÀÌÆ® Àü¿ë) MS Office XP (including Publisher 2002): http://microsoft.com/downloads/details.aspx?FamilyId=6F1FC4B0-29E9-44E0-A33D-AD6B4B6A8FF4&displaylang=en http://www.microsoft.com/office/ork/xp/journ/oxp1001a.htm (°ü¸®ÀÚ ¾÷µ¥ÀÌÆ® Àü¿ë) MS Project 2000ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=E53A52E7-431D-4580-9733-B92A2B7BFD0D&displaylang=en MS Project 2002ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=525BDE0A-0028-488A-8209-6E07D4603CCB&displaylang=en MS Visio 2002ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=55944490-13C2-4043-BA2A-17AF02E9C73E&displaylang=en MS VBA 5.0, 6.0, 6.2, 6.3 or Access 97 or Excel 97 or PowerPoint 97, Word 97/98(J), Visio 2000, Works Suite 2001, BS(Business Solutions) Great Plains 7.5, BS Solutions Dynamics 6.0, 7.0, BS Solomon 4.5, 5.0, 5.5, MS VBA ÆÐÄ¡(http://microsoft.com/downloads/details.aspx?FamilyId=DA1A7ABA-CD3D-458B-9729-AB9094C9BD3F&displaylang=en) 2. ¾ð¾î ¼±Åà ¸ñ·Ï¿¡¼ ÇØ´ç ¾ð¾î¸¦ ¼±ÅÃÇÑ ÈÄ <Go> ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 3. ÆÐÄ¡ ÆÄÀÏÀ» ´Ù¿î ¹Þ±â À§ÇØ <Download> ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 4. ÆÐÄ¡¸¦ ¼³Ä¡Çϱâ À§ÇØ ÆÄÀÏÀ» ½ÇÇà½ÃŲ´Ù. 5. ¼³Ä¡¸¦ ¿Ï·áÇϱâ À§Çؼ ½Ã½ºÅÛÀ» ÀçºÎÆÃ ÇÑ´Ù.
-- ȤÀº --
´ÙÀ½ Office Update¸¦ »ç¿ëÇÏ¿© ÀÌ º¸¾È ÆÐÄ¡¸¦ ¼³Ä¡ÇÒ ¼ö ÀÖ´Ù. http://www.office.microsoft.com/korea/ProductUpdates/default.aspx |
°ü·Ã URL |
CVE-2003-0347 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
13092 (ISS) |
|