MS Office Web Component(MS09-043) ¹× MS ATL(Active Template Library)(MS09-037) µîÀÇ Ãë¾àÁ¡¿¡ ´ëÇÑ 8¿ù MS Á¤±âº¸¾È¾÷µ¥ÀÌÆ®°¡ ¹ßÇ¥µÇ¾úÀ¸´Ï, Á¶¼ÓÈ÷ ÆÐÄ¡ÇϽñ⠹ٶø´Ï´Ù.
[MS09-036] ASP.NET Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¼ºñ½º °ÅºÎ ¹®Á¦
¡à ¿µÇâ
o ¿µÇâ ¹Þ´Â ½Ã½ºÅÛÀÇ ¼ºñ½º Áß´Ü ¶Ç´Â Àç½ÃÀÛ
¡à ¼³¸í
o ASP.NET¿¡¼ ½ºÄÉÁ층 ¿äûÀ» °ü¸®ÇÏ´Â ¹æ¹ý¿¡¼ ¼ºñ½º °ÅºÎ ¹®Á¦Á¡ ¹ß»ý
¡Ø ASP.NET : MS¿¡¼ Á¦°øÇÏ´Â µ¿Àû À¥ »çÀÌÆ®, °³¹ßÀ» Áö¿øÇϱâ À§ÇÑ À¥ ÀÀ¿ëÇÁ·Î±×·¥
ÇÁ·¹ÀÓ¿öÅ©
o °ø°ÝÀÚ´Â Á¶ÀÛµÈ À͸íÀÇ HTTP ¿äûÀ» ASP.NET ¸Å´ÏÀú¿¡ Àü´ÞÇÔÀ¸·Î½á °ü·Ã
À¥ ÀÀ¿ëÇÁ·Î±×·¥À» Àç½ÃÀÛÇϱâ Àü±îÁö ¿µÇâ ¹Þ´Â ½Ã½ºÅÛÀÇ ¹«ÀÀ´ä »óŸ¦ À¯¹ß½ÃÅ´
o °ü·ÃÃë¾àÁ¡ : Remote Unauthenticated Denial of Service in ASP.NET Vulnerability
(CVE-2009-1536)
o ¿µÇâ : ¼ºñ½º °ÅºÎ
o Á߿䵵 : Áß¿ä
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- MS .NET Framework 2.0 SP1, SP2 on Windows Vista, SP1
- MS .NET Framework 3.5, SP1 on Windows Vista, SP1
- MS .NET Framework 2.0 SP1, SP2 on Windows Vista x64 Edition, SP1
- MS .NET Framework 3.5, SP1 on Windows Vista x64 Edition, SP1
- MS .NET Framework 2.0 SP1, SP2 on Windows Server 2008 32bit, 64bit Edition
- MS .NET Framework 3.5, SP1 on Windows Server 2008 32bit, 64bit Edition
- MS .NET Framework 2.0 SP1, SP2 on Windows Server 2008 Itanium-based System
- MS .NET Framework 3.5, SP1 on Windows Server 2008 Itanium-based System
o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Microsoft Windows 2000 SP4
- Microsoft Windows XP SP2, SP3, x64 Edition SP2
- Microsoft Windows Server 2003 SP2, x64 Edition, SP2 for Itanium-based System
- Microsoft Windows Vista SP2, x64 Edition SP2
- Microsoft Windows Server 2008 32bit SP2, x64 SP4, Itanium-based System SP2
- Microsoft Windows 7 for 32bit, x64 Edition
- Microsoft Windows Server 2008 for x64, Itanium-based System
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-036.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-036.mspx
[MS09-037] MS ATL(Active Template Library) Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o ATL ÇÔ¼öµé¿¡¼ ½Å·ÚµÇÁö ¾Ê°Å³ª À߸øµÈ µ¥ÀÌÅ͸¦ ÀûÀýÇÏ°Ô Ã³¸®ÇÏÁö ¸øÇÏ´Â Ãë¾àÁ¡À¸·Î ÀÎÇØ
¿ø°ÝÄÚµå½ÇÇà°¡´É ¹®Á¦Á¡
¡Ø ATL : Active Template Library, C++ ¶Ç´Â ºñÁÖ¾ó C++¸¦ ÀÌ¿ëÇÏ¿© ASPÄڵ峪 ´Ù¸¥ ActiveX
ÇÁ·Î±×·¥ ÄÄÆ÷³ÍÆ®¸¦ ¸¸µé ¶§ »ç¿ëÇÏ´Â MS ÇÁ·Î±×·¥ ¶óÀ̺귯¸®
o °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ À¥ÆäÀÌÁö¸¦ ±¸ÃàÇÏ°í »ç¿ëÀÚ°¡ ¹æ¹®Çϵµ·Ï À¯µµÇϰųª,
Á¶ÀÛµÈ À̸ÞÀÏÀ» Àü¼ÛÇÏ¿© ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Microsoft Video ActiveX Control Vulnerability - CVE-2008-0015
- ATL Header Memcopy Vulnerability - CVE-2008-0020
- ATL Uninitalized Object Vulnerability - CVE-2009-0901
- ATL COM Initialization Vulnerability - CVE-2009-2493
- ATL Object Type Mismatch Vulnerability - CVE-2009-2494
o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà
o Á߿䵵 : ±ä±Þ
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Outlook Express 5.5 SP2, Outlook Express 6 SP1, Windows Media Player 9,
Windows ATL Component, DHTML Editing Component ActiveX Control on Windows 2000 SP4
- Outlook Express 6, Windows Media Player 9/10/11, Windows ATL Component, DHTML
Editing Component Active Control, MSWebDVD ActiveX Control on Windows XP SP2, SP3
- Outlook Express 6, Windows Media Player 10, Windows ATL Component, DHTML Editing
Component ActiveX Control, MSWebDVD ActiveX Control on Windows XP x64 Edition SP2
- Outlook Express 6, Windows Media Player 10, Windows ATL Component, DHTML Editing
Component ActiveX Control, MSWebDVD ActiveX Control on Windows Server 2003 SP2
- Outlook Express 6, Windows Media Player 10, Windows ATL Component, DHTML Component
ActiveX Control, MSWebDVD ActiveX Control on Windows Server 2003 x64 Edition SP2
- Outlook Express 6, Windows ATL Component, DHTML Editing Component ActiveX Control,
MSWebDVD ActiveX Control on Windows Server 2003 Itanium-based Systems SP2
- Windows Media Player 11, Windows ATL Component on Windows Vista, SP1, SP2
- Windows Media Player 11, Windows ATL Component on Windows Vista x64 SP1, SP2
- Windows Media Player 11, Windows ATL Component on Windows Server 2008 x64, SP2
- Windows Media Player 11, Windows ATL Component on Windows Server 2008 for
Itanium-based Systems, SP2
o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 7 for 32bit, x64 based Systems
- Windows Server 2008 R2 for x64, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-037.mspx
[MS09-038] Windows Media File ó¸® Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o MS Windows¿¡¼ Á¶ÀÛµÈ AVI ÆÄÀÏ Æ÷¸ËÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå ½ÇÇà ¹®Á¦Á¡ ¹ß»ý
o °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ À¥ÆäÀÌÁö, À̸ÞÀÏ µîÀ» ÅëÇÏ¿© »ç¿ëÀÚ·Î ÇÏ¿©±Ý Á¶ÀÛµÈ AVI ÆÄÀÏÀ» ¿¾î
º¸µµ·Ï À¯µµÇÔ. °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Malformed AVI Header Vulnerability - CVE-2009-1545
- AVI Integer Overflow Vulnerability - CVE-2009-1546
o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà
o Á߿䵵 : ±ä±Þ
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 2000 SP4
- Windows XP SP2, SP3, Professional x64 Edition SP2
- Windows Server 2003 SP2, x64 Edition SP2, Itanium-based Systems SP2
- Windows Vista, SP1, SP2
- Windows Vista x64, SP1, SP2
- Windows Server 2008 32bit, SP2
- Windows Server 2008 x64, SP2
- Windows Server 2008 Itanium-based System, SP2
o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 7 for 32bit, x64 based Systems
- Windows Server 2008 R2 for x64, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-038.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-038.mspx
[MS09-039] MS WINS Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o Windows WINS ¼ºñ½º¿¡¼ Á¶ÀÛµÈ WINS ÆÐŶÀ» ó¸®ÇÒ ¶§ ¹öÆÛ±æÀÌ °è»ê ¿À·ù·Î ÀÎÇÏ¿©
¿ø°ÝÄÚµå½ÇÇà ¹®Á¦Á¡ Á¸Àç
¡Ø WINS : Windows Internet Name Service, ³Ý¹ÙÀÌ¿À½º(NetBIOS)·Î ±¸¼ºµÈ ȯ°æ¿¡¼ÀÇ
ÄÄÇ»ÅÍ À̸§°ú IPÁÖ¼Ò¸¦ ¸ÊÇνÃÄÑÁÖ´Â ¼ºñ½º
o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¹× ±ÇÇÑ »ó½Â °¡´É
o °ü·ÃÃë¾àÁ¡ :
- WINS Heap Overflow Vulnerability - CVE-2009-1923
- WINS Integer Overflow Vulnerability - CVE-2009-1924
o ¿µÇâ : ¿ø°ÝÄÚµå
o Á߿䵵 : ±ä±Þ
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 2000 Server SP4
- Windows Server 2003 SP2, x64 Edition SP2, Itanium-based Systems SP2
o ¿µÇâ ¹Þ´ÂÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 2000 Professional SP4
- Windows XP SP2, SP3, Professional x64 Edition SP2
- Windows Vista, SP1, SP2
- Windows Vista x64, SP1, SP2
- Windows Server 2008 32bit, SP2
- Windows Server 2008 x64, SP2
- Windows Server 2008 Itanium-based System, SP2
- Windows 7 for 32bit, x64 Systems
- Windows Server 2008 R2 for x64-based, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-039.mspx
[MS09-040] MS Message Queuing ¼ºñ½º Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ Á¢±Ù ±ÇÇÑ È¹µæ ¹× ±ÇÇÑ »ó½Â
¡à ¼³¸í
o MS ¸Þ½ÃÁö Å¥ ¼ºñ½º¿¡¼ Á¶ÀÛµÈ IOCTL ¿äû¿¡ ´ëÇÑ ÀûÀýÇÑ °Ë»ç¸¦ ÇÏÁö ¸øÇØ À̸¦ ÆÄ½ÌÇÏ´Â
°úÁ¤¿¡¼ ±ÇÇÑ»ó½Â ¹®Á¦Á¡ Á¸Àç
¡Ø MS ¸Þ½ÃÁö Å¥ : MSMQ, À̱âÁ¾ ³×Æ®¿öÅ©»ó¿¡¼ ±¸µ¿µÇ´Â ÀÀ¿ëÇÁ·Î±×·¥ °£ ºñµ¿±âÀûÀ¸·Î
¸Þ½ÃÁö¸¦ Àü´ÞÇÒ ¼ö Àִ ť
o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡
- MSMQ Null Pointer Vulnerability - CVE-2009-1922
o ¿µÇâ : ±ÇÇÑ»ó½Â
o Á߿䵵 : Áß¿ä
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Microsoft Windows 2000 SP4
- Microsoft Windows XP SP2, Professional x64 Edition SP2
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Server 2003 x64 Edition SP2
- Microsoft Windows Server 2003 for Itanium-based Systems SP2
- Microsoft Windows Vista, x64 Edition
o ¿µÇâ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Microsoft Windows XP SP3
- Microsoft Windows Vista SP1, SP2
- Microsoft Windows Vista x64 Edition SP1, SP2
- Microsoft Windows Server 2008 for 32-bit Systems, SP2
- Microsoft Windows Server 2008 for x64-based Systems, SP2
- Microsoft Windows Server 2008 for Itanium-based Systems, SP2
- Windows 7 for 32bit, x64 Systems
- Windows Server 2008 R2 for x64-based, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-040.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-040.mspx
[MS09-041] MS ¿öÅ©½ºÅ×ÀÌ¼Ç ¼ºñ½º Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o À©µµ¿ìÁî ¿öÅ©½ºÅ×ÀÌ¼Ç ¼ºñ½º¿¡¼¡°ÀÌÁß ÇØÁ¦¡±°¡´É¼ºÀ¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦Á¡ Á¸Àç
¡Ø ÀÌÁß ÇØÁ¦ : Double Free, ÇÁ·Î±×·¥¿¡¼ ÇÒ´çµÈ ¸Þ¸ð¸® ¿µ¿ªÀÌ ÇØÁ¦µÈ ÈÄ ´Ù½Ã ÇØÁ¦µÇ¾î
¸Þ¸ð¸® °ü¸®»óÀÇ ¿¡·¯¸¦ À¯¹ß
o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Workstation Service Memory Corruption Vulnerability - CVE-2009-1544
o ¿µÇâ : ±ÇÇÑ»ó½Â
o Á߿䵵 : Áß¿ä
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Windows XP SP2, SP3
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 for Itanium-based Systems SP2
- Windows Vista, SP1, SP2
- Windows Vista x64 Edition, SP1, SP2
- Windows Server 2008 for 32-bit Systems, SP2
- Windows Server 2008 for x64-based Systems, SP2
- Windows Server 2008 for Itanium-based Systems, SP2
o ¿µÇâ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 2000 SP4
- Windows 7 for 32bit, x64 Systems
- Windows Server 2008 R2 for x64-based, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-041.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-041.mspx
[MS09-042] Telnet Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o MS ÅÚ³Ý(Telnet) ¼ºñ½º ³» ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦Á¡ Á¸Àç
o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Telnet Credential Reflection Vulnerability - CVE-2009-1930
o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà
o Á߿䵵 : Áß¿ä
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 2000 SP4
- Windows XP SP2, SP3
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 for Itanium-based Systems SP2
- Windows Vista, SP1, SP2
- Windows Vista x64 Edition, SP1, SP2
- Windows Server 2008 for 32-bit Systems, SP2
- Windows Server 2008 for x64-based Systems, SP2
- Windows Server 2008 for Itanium-based Systems, SP2
o ¿µÇâ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 7 for 32bit, x64 Systems
- Windows Server 2008 R2 for x64-based, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-042.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-042.mspx
[MS09-043] MS Office Web Component Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o Office Web Component Active ÄÁÆ®·Ñ ³» Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà °¡´É ¹®Á¦Á¡
¡Ø Office Web Component(OWC) : MS Office Á¦Ç°±º¿¡¼ ActiveX ÄÁÆ®·Ñ ÇüÅ·ΠÁ¦°øµÇ´Â
OLE ¿ä¼ÒµéÀÇ ±×·ì
o °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ À¥ÆäÀÌÁö¸¦ ±¸¼ºÇÑ ÈÄ À̸ÞÀÏ µîÀ» ÅëÇÏ¿© »ç¿ëÀÚ·Î ÇÏ¿©±Ý ¹æ¹®Çϵµ·Ï
À¯µµÇÔ. °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Office Web Components Memory Allocation Vulnerability - CVE-2009-0562
- Office Web Components Heap Corruption Vulnerability - CVE-2009-2496
- Office Web Components HTML Script Vulnerability - CVE-2009-1136
- Office Web Components Buffer Overflow Vulnerability - CVE-2009-1534
o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà
o Á߿䵵 : ±ä±Þ
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Microsoft Office XP SP3
- Microsoft Office 2003 SP3
- Microsoft Office 2000, XP, 2003 Web Components SP3
- Microsoft Office 2003 Web Components SP1 for 2007 Microsoft Office System
- Microsoft Internet Security and Acceleration Server 2004 Standard Edition SP3
- Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition SP3
- Microsoft Internet Security and Acceleration Server 2006 Standard Edition SP1
- Microsoft Internet Security and Acceleration Server 2006 Enterprise Edition SP1
- Microsoft Biztalk Server 2002
- Microsoft Visual Studio .NET 2003 SP1
- Microsoft Office Small Business Accouting 2006
o ¿µÇâ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- 2007 Microsoft Office Suite SP1, SP2
- Microsoft Office 2004, 2008 for Mac
- Microsoft Office PowerPoint Viewer 2003
- Microsoft Office Word Viewer 2003, SP3
- Microsoft Office Excel Viewer, Excel Viewer 2003, SP3
- Microsoft Office PowerPoint 2007 Viewer, SP1
- Microsoft Internet Security and Accerlation Server 2000 SP2
- Microsoft BizTalk Server 2004, 2006, 2009
- Microsoft Visual Studio 2005, SP1
- Microsoft Visual Studio 2008, SP1
- Microsoft Visual Studio 2010
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-043.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-043.mspx
[MS09-044] MS Remote Desktop Connection Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦
¡à ¿µÇâ
o °ø°ÝÀÚ°¡ ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ
¡à ¼³¸í
o MS Remote Desktop Connection¿¡¼ RDP¼¹ö·ÎºÎÅÍ Àü´ÞµÈ ƯÁ¤ÇÑ ÆÄ¶ó¹ÌÅ͸¦ ó¸®ÇÏ´Â
°úÁ¤¿¡¼ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦Á¡
¡Ø Remote Desktop Connection : ¿ø°Ý¿¡ Á¸ÀçÇÏ´Â PC¸¦ ·ÎÄÿ¡¼ Á¦¾îÇϱâ À§ÇÏ¿©
Á¦°øµÇ´Â ±â´É
o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É
o °ü·ÃÃë¾àÁ¡ :
- Remote Desktop Connection Heap Overflow Vulnerability - CVE-2009-1133
- Remote Desktop Connection ActiveX Heap Overflow Vulnerability - CVE-2009-1929
o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà
o Á߿䵵 : ±ä±Þ
¡à ÇØ´ç½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- RDP 5.0, 5.1, 5.2 on Windows 2000 SP4
- RDP 5.1, 5.2, 6.0, 6.1 on Windows XP SP2
- RDP 6.0 on Windows XP SP2
- RDP 5.2, 6.1 on Windows XP SP3
- RDP 5.2, 6.1 on Windows XP Professional x64 Edition SP2
- RDP 5.2, 6.0 on Windows Server 2003 SP2
- RDP 5.2, 6.0 on Windows Server 2003 x64 Edition SP2
- RDP 5.2 on Windows Server 2003 Itanium-based Systems SP2
- RDP 6.0 on Windows Vista, x64 Edition
- RDP 6.1 on Windows Vista SP1/SP2, x64 Edition SP1/SP2
- RDP 6.1 on Windows Server 2008 for 32-bit Systems, SP2
- RDP 6.1 on Windows Server 2008 for x64-based Systems, SP2
- RDP 6.1 on Windows Server 2008 for Itanium-based Systems, SP2
- Remote Desktop Connection client for Mac 2.0.1
o ¿µÇâ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
- Windows 7 for 32bit, x64 Systems
- Windows Server 2008 R2 for x64-based, Itanium-based Systems
¡à ÇØ°áÃ¥
o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
¡à ÂüÁ¶»çÀÌÆ®
o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-044.mspx
o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-044.mspx
|