English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28157
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í IBM ¿öÅ©½ºÅ×À̼ǰú ·¦Å¾ »ó¿¡ ¼³Ä¡µÈ eGatherer ActiveX ÄÁÆ®·ÑÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é 'RunEgatherer' ÇÔ¼ö ³»¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Ù. IBM eGatherer´Â IBMÀ¸·Î ¸®Æ÷Æ®µÇ´Â ¹®Á¦µéÀÇ ºÐ¼®À» µ½±â À§ÇØ »ç¿ëÀÚµéÀÇ ÄÄÇ»ÅͷκÎÅÍ ±¸¼º Á¤º¸¸¦ ¼öÁýÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. IBM eGatherer ActiveX ÄÁÆ®·Ñ 3.20.284.0 ÀÌÀüÀÇ ¹öÀüµéÀº 'RunEgatherer' ÇÔ¼ö ³»¿¡ Á¸ÀçÇÏ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. 'RunEgatherer' ÇÔ¼ö·Î ¾ÆÁÖ ±ä eGatherer ·Î±× Ãâ·Â Àμö¸¦ Àü´ÞÇÔÀ¸·Î½á ¿ø°ÝÁö °ø°ÝÀÚ´Â ¿µÇâ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼­ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃÅ°°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛ »ó¿¡ ¼³Ä¡µÈ IBM eGatherer ActiveX ÄÁÆ®·ÑÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www-306.ibm.com/pc/support/site.wss/MIGR-4R5VKC.html
http://www.securityfocus.com/archive/1/443471
http://secunia.com/advisories/21528/
http://www.frsirt.com/english/advisories/2006/3305
http://research.eeye.com/html/advisories/published/AD20060816.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM eGatherer ActiveX ÄÁÆ®·Ñ 3.20.284.0 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ IBM eGatherer ActiveX ÄÁÆ®·Ñ À¥ »çÀÌÆ®ÀÎ http://www-307.ibm.com/pc/support/IbmEgath.cab ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ eGatherer ActiveX ÄÁÆ®·Ñ ¹öÀü(3.20.284.0 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-4221 (CVE)
°ü·Ã URL 19554 (SecurityFocus)
°ü·Ã URL 28418 (ISS)