½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ Ä¿ÇǴнº Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
 FAQFAQ   °Ë»ö°Ë»ö   ¸â¹ö¸®½ºÆ®¸â¹ö¸®½ºÆ®   »ç¿ëÀÚ ±×·ì»ç¿ëÀÚ ±×·ì   »ç¿ëÀÚ µî·ÏÇϱâ»ç¿ëÀÚ µî·ÏÇϱâ 
 °³ÀÎ Á¤º¸°³ÀÎ Á¤º¸   ºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀ   ·Î±×Àηα×ÀΠ

°¡ÀÔ¾øÀÌ ´©±¸³ª ±ÛÀ» ¾µ ¼ö ÀÖ½À´Ï´Ù. °øÁö»çÇ׿¡ ´ëÇÑ ´ñ±Û±îÁöµµ..




BBS >> ¼³Ä¡, ¿î¿µ Q&A | ³×Æ®¿÷, º¸¾È Q&A | ÀÏ¹Ý Q&A || Á¤º¸¸¶´ç | AWS || ÀÚÀ¯°Ô½ÃÆÇ | ±¸Àα¸Á÷ || °øÁö»çÇ× | ÀǰßÁ¦½Ã
MS º¸¾ÈÆÐÄ¡ 7°Ç ¹ßÇ¥ (10.16ÀÏ)

 
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â  
±Û¾´ÀÌ ¸Þ½ÃÁö
truefeel
Ä«Æä °ü¸®ÀÚ


°¡ÀÔ: 2003³â 7¿ù 24ÀÏ
¿Ã¸° ±Û: 1277
À§Ä¡: ´ëÇѹα¹

¿Ã¸®±â¿Ã·ÁÁü: 2003.10.20 ¿ù, 10:33 am    ÁÖÁ¦: MS º¸¾ÈÆÐÄ¡ 7°Ç ¹ßÇ¥ (10.16ÀÏ) Àοë°ú ÇÔ²² ´äº¯

´Ù¸¥ °÷¿¡¼­µµ ÆÐÄ¡ ¹ßÇ¥ ±ÛÀ» ºÃ´Âµ¥, ÀÌÁ¦ ¿Ã¸®´Â°Ô Á» ´ÊÀº°¨ÀÌ Àֳ׿ä.
´ÙÀ½Àº sec-info ¸ÞÀϸµ¿¡¼­ ¹ÞÀº ³»¿ëÀÔ´Ï´Ù. (º¸³½ÀÌÀÇ ¸ÞÀÏÁÖ¼Ò´Â »ý·«ÇßÀ½)

Àοë:

º¸³½ÀÌ: Kyongwon Cho <....>
Á¦¸ñ: [ ¾Èö¼ö¿¬±¸¼Ò] MS º¸¾ÈÆÐÄ¡ 7°Ç ¹ßÇ¥
³¯Â¥: 16 Oct 2003 10:35:30 +0900

¾È³çÇϼ¼¿ä

¾Èö¼ö¿¬±¸¼Ò ½ÃÅ¥¸®Æ¼´ëÀÀ¼¾ÅÍÀÇ Á¶°æ¿øÀÔ´Ï´Ù.

10/16ÀÏ MS¿¡¼­ 7°ÇÀÇ º¸¾ÈÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù.

5°Ç(MS03-041~045)Àº Windows½Ã½ºÅÛ¿¡ °ü·ÃµÈ º¸¾È ÆÐÄ¡À̸ç 2°Ç(MS03-046~047)Àº Exchange Server »ç¿ëÀÚ¿¡°Ô¸¸ ÇØ´ç µË´Ï´Ù.

ÀÚ¼¼ÇÑ ³»¿ëÀº ¾Æ·¡ URLÀ» ÂüÁ¶ÇÏ½Ã¸é µË´Ï´Ù.
¿µ¹®: http://www.microsoft.com/technet/security/current.asp
ÇѱÛ: http://www.microsoft.com/korea/technet/security/current.asp



°£·«ÇÑ ¼³¸íÀº ´ÙÀ½°ú °°½À´Ï´Ù.

- MS03-047: Exchange Server 5.5 Outlook Web AccessÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ »çÀÌÆ® °£ ½ºÅ©¸³ÆÃ ħÀÔ ¹®Á¦

À§Çèµî±Þ : Moderate
OWA(Outlook Web Access)¿¡¼­ XSS(Cross-site Scripting)Ãë¾àÁ¡À¸·Î OWA´Â Exchange Server¼³Ä¡½Ã µðÆúÆ®·Î´Â »ç¿ëÀÌ ¾ÈµÇÁö ¾Ê½À´Ï´Ù. ÁַΠƯÁ¤ ±â¾÷¿¡¼­ ±×·ì¿þ¾î·Î »ç¿ëÇÒ¶§ »ç¿ëµË´Ï´Ù.
5.5¹öÀü¿¡¼­¸¸ ÇØ´çµÇ¸ç 2000,2003¹öÀüÀº ÇØ´çµÇÁö ¾Ê½À´Ï´Ù.
ActiveÇÑ °ø°ÝÄڵ带 »ç¿ëÇÑ °ø°ÝÀÌ ¾Æ´Ñ XSSÃë¾àÁ¡À» »ç¿ëÇÑ Å©·¡Å· °¡´É¼ºÀÌ Á¸ÀçÇÕ´Ï´Ù.

- MS03-046: Exchange ServerÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÀÓÀÇ ÄÚµå ½ÇÇà ¹®Á¦

À§Çèµî±Þ : Exchange Server 5.5 Important / Exchange 2000 Server Critical
5.5¿Í 2000¹öÀü¿¡¼­ ÇØ´çµÇ¸ç DoS°ø°ÝÀ¸·Î Exchange¼­¹öÀÇ SMTP¼­ºñ½º¿¡ Àå¾Ö°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. 2000¹öÀüÀÇ °æ¿ì¿¡´Â Buffer OverrunÀ¸·Î ´Ù¸¥ °ø°ÝÀÌ °¡´ÉÇÒ ¼öµµ ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.

- MS03-045: ListBox ¹× ComboBox ÄÁÆ®·ÑÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦

À§Çèµî±Þ : NT,XP,2003 Low / 2000 Important
ME¹öÀüÀ» Á¦¿ÜÇÑ ¸ðµç Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ListBox, ComboBox control¿¡ buffer overrunÀÌ Á¸ÀçÇÕ´Ï´Ù. °ø°ÝÀ» ÇϱâÀ§Çؼ­´Â ½Ã½ºÅÛ¿¡ logonÀ» ÇÏ¿©¾ß Çϱ⶧¹®¿¡ ½ÇÁ¦ °ø°Ý¿¡ »ç¿ëµÇ±â´Â Èûµì´Ï´Ù.(Windows½Ã½ºÅÛÀǰæ¿ì localÃë¾àÁ¡Àº ÀϹÝÀûÀ¸·Î Å« Àǹ̰¡ ¾ø½À´Ï´Ù.)
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.

- MS03-044: Windows µµ¿ò¸» ¹× Áö¿ø ¼¾ÅÍÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ½Ã½ºÅÛ ¼Õ»ó ¹®Á¦

À§Çèµî±Þ : ME,NT,2000 Low / XP,2003 Critical
¸ðµç¹öÀüÀÇ Windows½Ã½ºÅÛ¿¡ ÇØ´çµÇ¸ç HCPÇÁ·ÎÅäÄÝ(Windows½Ã½ºÅÛÀÇ Help¿¡ °ü·ÃµÈ ÇÁ·ÎÅäÄÝ)¿¡´ëÇÑ Ãë¾àÁ¡ ÀÔ´Ï´Ù. À§Á¶µÈ À¤ÆäÀÌÁö¿¡ ¹æ¹® ȤÀº HTML¸ÞÀϵ ÀÇÇØ¼­ Buffer OverrunÀÌ ¹ß»ýÇÏ¿© °ø°ÝÇÒ ¼ö ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.

- MS03-043: ¸Þ½ÅÀú ¼­ºñ½ºÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦

À§Çèµî±Þ : NT,2000,XP Critical / 2003 Moderate
ME¸¦ Á¦¿ÜÇÑ ¸ðµç Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ¸Þ½ÅÀú¼­ºñ½º(ÆË¾÷â ¶ß´Â net send¿Í °°Àº ¸Þ½ÅÀú¼­ºñ½º¸¦ ¸»ÇÕ´Ï´Ù. MSN¸Þ½ÅÀú¿Í´Â °ü·Ã ¾ø½À´Ï´Ù.)¿¡ Buffer overrunÀÌ Á¸ÀçÇÕ´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.

- MS03-042: Windows ¹®Á¦ ÇØ°á»çÀÇ ¹öÆÛ ¿À¹öÇ÷ηΠÀÎÇÑ ActiveX ÄÁÆ®·ÑÀÇ ÄÚµå ½ÇÇà ¹®Á¦

À§Çèµî±Þ : 2000 Critical
2000½Ã½ºÅÛ¿¡¼­¸¸ ÇØ´çµË´Ï´Ù. Á¶ÀÛµÈ HTML¸ÞÀÏÀ̳ª À¥»çÀÌÆ® ¹æ¹®½Ã ActiveX controlÀÇ buffer overrunÃë¾àÁ¡À» »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç È®ÀεÇÁö ¾Ê¾Ò½À´Ï´Ù.

- MS03-041: Authenticode È®ÀÎÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : NT,2000,XP Critical / 2003 Moderate
ME¸¦ Á¦¿ÜÇÑ Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ¸Þ¸ð¸®°¡ ºÎÁ·ÇÒ¶§(low memory condition) ActiveX controlÀ» ÀÎÁõÀ» ¹ÞÁö¾Ê°í ¼³Ä¡ÇÏ´Â Ãë¾àÁ¡ÀÔ´Ï´Ù. MS03-042¿Í ¸¶Âù°¡Áö·Î Á¶ÀÛµÈ HTML¸ÞÀÏ, À¥»çÀÌÆ®¹æ¹®µîÀ» ÅëÇØ °ø°Ý´çÇÒ ¼ö ÀÖ½À´Ï´Ù.



°¨»çÇÕ´Ï´Ù.

= ¾Èö¼ö¿¬±¸¼Ò

À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â ±Û ¿Ã¸°ÀÌÀÇ À¥»çÀÌÆ® ¹æ¹®
ÀÌÀü ±Û Ç¥½Ã:   
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸ ½Ã°£´ë: GMT + 9 ½Ã°£(Çѱ¹)
ÆäÀÌÁö 1 Áß 1

 
°Ç³Ê¶Ù±â:  
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù
¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù
ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù


Powered by phpBB © 2001, 2005 phpBB Group