|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
¿Ã·ÁÁü: 2003.10.20 ¿ù, 10:33 am ÁÖÁ¦: MS º¸¾ÈÆÐÄ¡ 7°Ç ¹ßÇ¥ (10.16ÀÏ) |
|
|
´Ù¸¥ °÷¿¡¼µµ ÆÐÄ¡ ¹ßÇ¥ ±ÛÀ» ºÃ´Âµ¥, ÀÌÁ¦ ¿Ã¸®´Â°Ô Á» ´ÊÀº°¨ÀÌ Àֳ׿ä.
´ÙÀ½Àº sec-info ¸ÞÀϸµ¿¡¼ ¹ÞÀº ³»¿ëÀÔ´Ï´Ù. (º¸³½ÀÌÀÇ ¸ÞÀÏÁÖ¼Ò´Â »ý·«ÇßÀ½)
Àοë: |
º¸³½ÀÌ: Kyongwon Cho <....>
Á¦¸ñ: [ ¾Èö¼ö¿¬±¸¼Ò] MS º¸¾ÈÆÐÄ¡ 7°Ç ¹ßÇ¥
³¯Â¥: 16 Oct 2003 10:35:30 +0900
¾È³çÇϼ¼¿ä
¾Èö¼ö¿¬±¸¼Ò ½ÃÅ¥¸®Æ¼´ëÀÀ¼¾ÅÍÀÇ Á¶°æ¿øÀÔ´Ï´Ù.
10/16ÀÏ MS¿¡¼ 7°ÇÀÇ º¸¾ÈÆÐÄ¡¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù.
5°Ç(MS03-041~045)Àº Windows½Ã½ºÅÛ¿¡ °ü·ÃµÈ º¸¾È ÆÐÄ¡À̸ç 2°Ç(MS03-046~047)Àº Exchange Server »ç¿ëÀÚ¿¡°Ô¸¸ ÇØ´ç µË´Ï´Ù.
ÀÚ¼¼ÇÑ ³»¿ëÀº ¾Æ·¡ URLÀ» ÂüÁ¶ÇÏ½Ã¸é µË´Ï´Ù.
¿µ¹®: http://www.microsoft.com/technet/security/current.asp
ÇѱÛ: http://www.microsoft.com/korea/technet/security/current.asp
°£·«ÇÑ ¼³¸íÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- MS03-047: Exchange Server 5.5 Outlook Web AccessÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ »çÀÌÆ® °£ ½ºÅ©¸³ÆÃ ħÀÔ ¹®Á¦
À§Çèµî±Þ : Moderate
OWA(Outlook Web Access)¿¡¼ XSS(Cross-site Scripting)Ãë¾àÁ¡À¸·Î OWA´Â Exchange Server¼³Ä¡½Ã µðÆúÆ®·Î´Â »ç¿ëÀÌ ¾ÈµÇÁö ¾Ê½À´Ï´Ù. ÁַΠƯÁ¤ ±â¾÷¿¡¼ ±×·ì¿þ¾î·Î »ç¿ëÇÒ¶§ »ç¿ëµË´Ï´Ù.
5.5¹öÀü¿¡¼¸¸ ÇØ´çµÇ¸ç 2000,2003¹öÀüÀº ÇØ´çµÇÁö ¾Ê½À´Ï´Ù.
ActiveÇÑ °ø°ÝÄڵ带 »ç¿ëÇÑ °ø°ÝÀÌ ¾Æ´Ñ XSSÃë¾àÁ¡À» »ç¿ëÇÑ Å©·¡Å· °¡´É¼ºÀÌ Á¸ÀçÇÕ´Ï´Ù.
- MS03-046: Exchange ServerÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÀÓÀÇ ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : Exchange Server 5.5 Important / Exchange 2000 Server Critical
5.5¿Í 2000¹öÀü¿¡¼ ÇØ´çµÇ¸ç DoS°ø°ÝÀ¸·Î Exchange¼¹öÀÇ SMTP¼ºñ½º¿¡ Àå¾Ö°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. 2000¹öÀüÀÇ °æ¿ì¿¡´Â Buffer OverrunÀ¸·Î ´Ù¸¥ °ø°ÝÀÌ °¡´ÉÇÒ ¼öµµ ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.
- MS03-045: ListBox ¹× ComboBox ÄÁÆ®·ÑÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : NT,XP,2003 Low / 2000 Important
ME¹öÀüÀ» Á¦¿ÜÇÑ ¸ðµç Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ListBox, ComboBox control¿¡ buffer overrunÀÌ Á¸ÀçÇÕ´Ï´Ù. °ø°ÝÀ» ÇϱâÀ§Çؼ´Â ½Ã½ºÅÛ¿¡ logonÀ» ÇÏ¿©¾ß Çϱ⶧¹®¿¡ ½ÇÁ¦ °ø°Ý¿¡ »ç¿ëµÇ±â´Â Èûµì´Ï´Ù.(Windows½Ã½ºÅÛÀǰæ¿ì localÃë¾àÁ¡Àº ÀϹÝÀûÀ¸·Î Å« Àǹ̰¡ ¾ø½À´Ï´Ù.)
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.
- MS03-044: Windows µµ¿ò¸» ¹× Áö¿ø ¼¾ÅÍÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ½Ã½ºÅÛ ¼Õ»ó ¹®Á¦
À§Çèµî±Þ : ME,NT,2000 Low / XP,2003 Critical
¸ðµç¹öÀüÀÇ Windows½Ã½ºÅÛ¿¡ ÇØ´çµÇ¸ç HCPÇÁ·ÎÅäÄÝ(Windows½Ã½ºÅÛÀÇ Help¿¡ °ü·ÃµÈ ÇÁ·ÎÅäÄÝ)¿¡´ëÇÑ Ãë¾àÁ¡ ÀÔ´Ï´Ù. À§Á¶µÈ À¤ÆäÀÌÁö¿¡ ¹æ¹® ȤÀº HTML¸ÞÀϵ ÀÇÇØ¼ Buffer OverrunÀÌ ¹ß»ýÇÏ¿© °ø°ÝÇÒ ¼ö ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.
- MS03-043: ¸Þ½ÅÀú ¼ºñ½ºÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : NT,2000,XP Critical / 2003 Moderate
ME¸¦ Á¦¿ÜÇÑ ¸ðµç Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ¸Þ½ÅÀú¼ºñ½º(ÆË¾÷â ¶ß´Â net send¿Í °°Àº ¸Þ½ÅÀú¼ºñ½º¸¦ ¸»ÇÕ´Ï´Ù. MSN¸Þ½ÅÀú¿Í´Â °ü·Ã ¾ø½À´Ï´Ù.)¿¡ Buffer overrunÀÌ Á¸ÀçÇÕ´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù.
- MS03-042: Windows ¹®Á¦ ÇØ°á»çÀÇ ¹öÆÛ ¿À¹öÇ÷ηΠÀÎÇÑ ActiveX ÄÁÆ®·ÑÀÇ ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : 2000 Critical
2000½Ã½ºÅÛ¿¡¼¸¸ ÇØ´çµË´Ï´Ù. Á¶ÀÛµÈ HTML¸ÞÀÏÀ̳ª À¥»çÀÌÆ® ¹æ¹®½Ã ActiveX controlÀÇ buffer overrunÃë¾àÁ¡À» »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
°ü·Ã °ø°ÝÄÚµå´Â ÇöÀç È®ÀεÇÁö ¾Ê¾Ò½À´Ï´Ù.
- MS03-041: Authenticode È®ÀÎÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦
À§Çèµî±Þ : NT,2000,XP Critical / 2003 Moderate
ME¸¦ Á¦¿ÜÇÑ Windows½Ã½ºÅÛ¿¡ ÇØ´çµË´Ï´Ù. ¸Þ¸ð¸®°¡ ºÎÁ·ÇÒ¶§(low memory condition) ActiveX controlÀ» ÀÎÁõÀ» ¹ÞÁö¾Ê°í ¼³Ä¡ÇÏ´Â Ãë¾àÁ¡ÀÔ´Ï´Ù. MS03-042¿Í ¸¶Âù°¡Áö·Î Á¶ÀÛµÈ HTML¸ÞÀÏ, À¥»çÀÌÆ®¹æ¹®µîÀ» ÅëÇØ °ø°Ý´çÇÒ ¼ö ÀÖ½À´Ï´Ù.
°¨»çÇÕ´Ï´Ù.
= ¾Èö¼ö¿¬±¸¼Ò
|
|
|
À§·Î |
|
 |
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|