English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28053
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'VBA(Visual Basic for Applications)ÀÇ °áÇÔÀ¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(822715)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù.
MS VBA´Â Ŭ¶óÀÌ¾ðÆ® µ¥½ºÅ©Åé ÆÐŰÁö ÀÀ¿ë ÇÁ·Î±×·¥À» °³¹ßÇϰí À̵éÀ» ±âÁ¸ µ¥ÀÌÅÍ ¹× ½Ã½ºÅÛ°ú ÅëÇÕÇÏ´Â °³¹ß ±â¼ú·Î½á, MS ¿ÀÇǽº Á¦Ç°¿¡ Æ÷ÇÔµÇ¾î Æ¯Á¤ ±â´ÉÀ» ¼öÇàÇϱâ À§ÇØ È°¿ëµÈ´Ù. VBA 5.0, 6,0, 6,2 ¶Ç´Â 6.3 ¹öÀüÀÇ °æ¿ì, ÀÀ¿ëÇÁ·Î±×·¥¿¡¼­ ¹®¼­°¡ ¿­¸± ¶§ VBA¿¡ Àü´ÞµÇ´Â ÀϺΠ¹®¼­ÀÇ ¼Ó¼º(properties)ÀÌ ¿Ã¹Ù¸£°Ô °Ë»çµÇÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§Çؼ­, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¿öµå ¹®¼­, ¿¢¼¿ ½ºÇÁ·¹µå ½¬Æ®, ÆÄ¿ö Æ÷ÀÎÆ® ÇÁ¸®Á¨Å×À̼ǰú °°ÀÌ VBA¸¦ Áö¿øÇÏ´Â Àß Á¶ÀÛµÈ ¹®¼­¸¦ ¸¸µé°í, »ç¿ëÀÚ°¡ ÀÌ ¹®¼­¸¦ ¿­µµ·Ï À¯µµÇÑ´Ù. ÀÏ´Ü ¾ÇÀÇÀûÀÎ ¹®¼­°¡ ¿­¸®°Ô µÇ¸é, ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ°í ¿ø°ÝÁö °ø°ÝÀÚµéÀº ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÑ »ç¿ëÀÚ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/MS03-037.asp
http://archives.neohapsis.com/archives/bugtraq/2003-09/0037.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Visual Basic for Applications SDK 5.0 , 6,0, 6.2, 6.3
¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¸¦ Æ÷ÇÔÇÏ´Â Á¦Ç°:
Microsoft Access 97, 2000, 2002
Microsoft Excel 97, 2000, 2002
Microsoft PowerPoint 97, 2000, 2002
Microsoft Project 2000, 2002
Microsoft Publisher 2002
Microsoft Visio 2000, 2002
Microsoft Word 97, 98(J), 2000, 2002
Microsoft Works Suite 2001, 2002, 2003
Microsoft Business Solutions Great Plains 7.5
Microsoft Business Solutions Dynamics 6.0, 7.0
Microsoft Business Solutions eEnterprise 6.0, 7.0
Microsoft Business Solutions Solomon 4.5, 5.0, 5,5
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-037¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/MS03-037.asp

1. ´ÙÀ½ÀÇ ÆäÀÌÁö¸¦ ¿¬´Ù:
MS Office 2000ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=E2CCE199-9C4A-4EEC-A3EC-9F738017F275&displaylang=en
http://www.microsoft.com/office/ork/xp/journ/o2k0901a.htm (°ü¸®ÀÚ ¾÷µ¥ÀÌÆ® Àü¿ë)
MS Office XP (including Publisher 2002): http://microsoft.com/downloads/details.aspx?FamilyId=6F1FC4B0-29E9-44E0-A33D-AD6B4B6A8FF4&displaylang=en
http://www.microsoft.com/office/ork/xp/journ/oxp1001a.htm (°ü¸®ÀÚ ¾÷µ¥ÀÌÆ® Àü¿ë)
MS Project 2000ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=E53A52E7-431D-4580-9733-B92A2B7BFD0D&displaylang=en
MS Project 2002ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=525BDE0A-0028-488A-8209-6E07D4603CCB&displaylang=en
MS Visio 2002ÀÇ °æ¿ì, http://microsoft.com/downloads/details.aspx?FamilyId=55944490-13C2-4043-BA2A-17AF02E9C73E&displaylang=en
MS VBA 5.0, 6.0, 6.2, 6.3 or Access 97 or Excel 97 or PowerPoint 97, Word 97/98(J), Visio 2000, Works Suite 2001, BS(Business Solutions) Great Plains 7.5, BS Solutions Dynamics 6.0, 7.0, BS Solomon 4.5, 5.0, 5.5, MS VBA ÆÐÄ¡(http://microsoft.com/downloads/details.aspx?FamilyId=DA1A7ABA-CD3D-458B-9729-AB9094C9BD3F&displaylang=en)
2. ¾ð¾î ¼±Åà ¸ñ·Ï¿¡¼­ ÇØ´ç ¾ð¾î¸¦ ¼±ÅÃÇÑ ÈÄ <Go> ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
3. ÆÐÄ¡ ÆÄÀÏÀ» ´Ù¿î ¹Þ±â À§ÇØ <Download> ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
4. ÆÐÄ¡¸¦ ¼³Ä¡Çϱâ À§ÇØ ÆÄÀÏÀ» ½ÇÇà½ÃŲ´Ù.
5. ¼³Ä¡¸¦ ¿Ï·áÇϱâ À§Çؼ­ ½Ã½ºÅÛÀ» ÀçºÎÆÃ ÇÑ´Ù.

-- ȤÀº --

´ÙÀ½ Office Update¸¦ »ç¿ëÇÏ¿© ÀÌ º¸¾È ÆÐÄ¡¸¦ ¼³Ä¡ÇÒ ¼ö ÀÖ´Ù.
http://www.office.microsoft.com/korea/ProductUpdates/default.aspx
°ü·Ã URL CVE-2003-0347 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 13092 (ISS)