|
Á¦¸ñ |
[Çʵ¶][MS º¸¾È¾÷µ¥ÀÌÆ®]2009³â 6¿ù MS Á¤±â º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í |
Á¶È¸¼ö |
2,961°Ç |
MS Office PowerPoint¿¡¼ ÇØÅ·¿¡ ¾Ç¿ë °¡´ÉÇÑ Ãë¾àÁ¡¿¡ ´ëÇÑ 6¿ù MS Á¤±âº¸¾È¾÷µ¥ÀÌÆ®°¡ ¹ßÇ¥µÇ¾úÀ¸´Ï, Á¶¼ÓÈ÷ ÆÐÄ¡ÇϽñ⠹ٶø´Ï´Ù.
[MS09-018] Active Directory Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o »ç¿ëÀÚ ½Ã½ºÅÛ¿¡¼ °ø°ÝÀÚ°¡ Àü¼ÛÇÑ Á¶ÀÛµÈ LDAP ȤÀº LDAPS ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå ½ÇÇàÃë¾àÁ¡ Á¸Àç ¡Ø LDAP : Lightweight Directory Access Protocol, ÀÎÅÍ³Ý µð·ºÅ丮¸¦ ¿¬°á, °Ë»ö ¹× ¼öÁ¤Çϴµ¥ »ç¿ëµÇ´Â ÇÁ·ÎÅäÄÝ ¡Ø LDAPS : LDAP over SSL, ÆÐŶ ¾Ïȣȸ¦ À§Çؼ SSL ä³ÎÀ» ÀÌ¿ëÇÑ LDAP Åë½Å o Ãë¾àÁ¡ °ø°Ý ½Ã °ø°ÝÀÚ´Â ¼¹ö ¼ºñ½º°¡ µ¿ÀÛÁßÀÎ ÄÄÇ»ÅÍ¿¡ Á¶ÀÛµÈ ³×Æ®¿öÅ© ¸Þ½ÃÁö¸¦ Àü¼Û. °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ÇÁ·Î±×·¥ ¼³Ä¡, »èÁ¦, °èÁ¤ »ý¼º µî ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É o °ü·ÃÃë¾àÁ¡ : - Active Directory Invalid Free Vulnerability - CVE-2009-1138 - Active Directory Memory Leak Vulnerability - CVE-2009-1139 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Active Directory on Microsoft Windows 2000 Server SP4 - Active Directory Application Mode on Windows XP Professional SP2, SP3 - Active Directory Application Mode on Windows XP Professional x64 Edition SP2 - Active Directory on Windows Server 2003 SP2 - Active Directory Application Mode on Windows Server 2003 SP2 - Active Directory on Windows Server 2003 x64 Edition SP2 - Active Directory Application Mode on Windows Server 2003 x64 Edition SP2 - Active Directory on Windows Server 2003 SP2 for Itanium-based Systems o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Active Directory on Windows Server 2008 for 32-bit Systems, SP2 - Active Directory Lightweight Directory Service on Windows Server 2008 for 32-bit Systems, SP2 - Active Directory on Windows Server 2008 for x64-based Systems, SP2 - Active Directory Lightweight Directory Service on Windows Server 2008 for x64-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-018.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-018.mspx
[MS09-019] Internet Explorer ´©Àû º¸¾È¾÷µ¥ÀÌÆ® ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o Internet Explorer¿¡¼ ÃʱâȵÇÁö ¾ÊÀº ¸Þ¸ð¸®¿¡ Á¢±ÙÇϰųª Á¶ÀÛµÈ ÆÄÀÏÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¹ß»ý ÇÏ´Â ¸Þ¸ð¸® ¹®Á¦·Î ÀÎÇÏ¿© ¿ø°ÝÄڵ尡 ½ÇÇàµÉ ¼ö ÀÖÀ½ o °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ À¥ »çÀÌÆ®¸¦ ±¸¼ºÇÏ¿© »ç¿ëÀÚ°¡ ÇØ´ç »çÀÌÆ®¿¡ ¹æ¹®Çϵµ·Ï À¯µµÇÔ. °ø°ÝÀÌ ¼º°ø ÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É o °ü·ÃÃë¾àÁ¡ : - Race Condition Cross-Domain Information Disclosure Vulnerability - CVE-2007-3091 - Cross-Domain Information Disclosure Vulnerability - CVE-2009-1140 - DHTML Object Memory Corruption - CVE-2009-1141 - HTML Object Memory Corruption - CVE-2009-1528 - Uninitialized Memory Corruption Vulnerability - CVE-2009-1529 - HTML Objects Memory Corruption Vulnerability - CVE-2009-1530 - HTML Object Memory Corruption Vulnerability - CVE-2009-1531 - HTML Object Memory Corruption Vulnerability - CVE-2009-1532 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ - Internet Explorer 5.01 SP4 on Microsoft Windows 2000 SP4 - Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4 - Internet Explorer 6 on Windows XP SP2, SP3 - Internet Explorer 6 on Windows XP Professional x64 Edition SP2 - Internet Explorer 6 on Windows Server 2003 SP2 - Internet Explorer 6 on Windows Server 2003 x64 Edition SP2 - Internet Explorer 6 on Windows Server 2003 SP2 for Itanium-based Systems - Internet Explorer 7 on Windows XP SP2, SP3 - Internet Explorer 7 on Windows XP Professional x64 Edition SP2 - Internet Explorer 7 on Windows Server 2003 SP2 - Internet Explorer 7 on Windows Server 2003 x64 Edition SP2 - Internet Explorer 7 on Windows Server 2003 SP2 for Itanium-based Systems - Internet Explorer 7 on Windows Vista, SP1, SP2 - Internet Explorer 7 on Windows Vista x64 Edition, SP1, SP2 - Internet Explorer 7 on Windows Server 2008 for 32-bit Systems, SP2 - Internet Explorer 7 on Windows Server 2008 for x64-based Systems, SP2 - Internet Explorer 7 on Windows Server 2008 for Itanium-based Systems, SP2 - Internet Explorer 8 on Windows XP SP2, SP3 - Internet Explorer 8 on Windows XP Professional x64 Edition SP2 - Internet Explorer 8 on Windows Server 2003 SP2 - Internet Explorer 8 on Windows Server 2003 x64 Edition SP2 - Internet Explorer 8 on Windows Vista, SP1, SP2 - Internet Explorer 8 on Windows Vista x64 Edition, SP1, SP2 - Internet Explorer 8 on Windows Server 2008 for 32-bit Systems, SP2 - Internet Explorer 8 on Windows Server 2008 for x64-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-019.mspx
[MS09-020] IIS Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Â ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ½ ¡à ¼³¸í o »ç¿ëÀÚ ½Ã½ºÅÛ¿¡¼ °ø°ÝÀÚ°¡ Àü¼ÛÇÑ Á¶ÀÛµÈ HTTP ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå ½ÇÇàÃë¾àÁ¡ Á¸Àç o Ãë¾àÁ¡ °ø°Ý ½Ã °ø°ÝÀÚ´Â ¼¹ö ¼ºñ½º°¡ µ¿ÀÛÁßÀÎ ÄÄÇ»ÅÍ¿¡ Á¶ÀÛµÈ ³×Æ®¿öÅ© ¸Þ½ÃÁö¸¦ Àü¼Û. °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ Á¢±ÙÇÒ ¼ö ÀÖ´Â ±ÇÇÑ È¹µæ °¡´É o °ü·ÃÃë¾àÁ¡ : - IIS 5.0 WebDAV Authentication Bypass Vulnerability - CVE-2009-1122 - IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability - CVE-2009-1535 o ¿µÇâ : ±ÇÇÑ»ó½Â o Áß¿äµµ : Áß¿ä ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Internet Information Services 5.0 on Microsoft Windows 2000 Server SP4 - Internet Information Services 5.1 on Windows XP Professional SP2, SP3 - Internet Information Services 6.0 on Windows XP Professional x64 Edition SP2 - Internet Information Services 6.0 on Windows Server 2003 SP2 - Internet Information Services 6.0 on Windows Server 2003 x64 Edition SP2 - Internet Information Services 6.0 on Windows Server 2003 SP2 for Itanium-based Systems o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Internet Information Services 7.0 on Windows Vista, SP1, SP2 - Internet Information Services 7.0 on Windows Vista x64 Edition, SP1, SP2 - Internet Information Services 7.0 on Windows Server 2008 for 32-bit Systems, SP2 - Internet Information Services 7.0 on Windows Server 2008 for x64-based Systems, SP2 - Internet Information Services 7.0 on Windows Server 2008 for Itanium-based Systems, SP2
¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-020.mspx
[MS09-021] MS Office Excel Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o Microsoft Office ExcelÀÌ ºñÁ¤»óÀûÀÎ ·¹Äڵ带 Æ÷ÇÔÇÑ ¿¢¼¿ ÆÄÀÏÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ÀÌ Á¸Àç o °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ÇÁ·Î±×·¥ ¼³Ä¡, »èÁ¦, °èÁ¤ »ý¼º µî ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É o °ü·ÃÃë¾àÁ¡ : - Record Pointer Corruption Vulnerability - CVE-2009-0549 - Object Record Corruption Vulnerability - CVE-2009-0557 - Array Indexing Memory Corruption Vulnerability - CVE-2009-0558 - String Copy Stack-Based Overrun Vulnerability - CVE-2009-0559 - Field Sanitization Memory Corruption Vulnerability - CVE-2009-0560 - Record Integer Overflow Vulnerability - CVE-2009-0561 - Record Pointer Corruption Vulnerability - CVE-2009-1134 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Office 2000 SP3 - Microsoft Office XP SP3 - Microsoft Office 2003 SP3 - 2007 Microsoft Office System SP1, SP2 - Microsoft Office 2004 for Mac - Microsoft Office 2008 for Mac - Open XML File Format Converter for Mac - Microsoft Office Excel Viewer 2003 SP3 - Microsoft Office Excel Viewer - Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1, SP2 - Microsoft Office SharePoint Server 2007 SP1, SP2 (32-bit editions) - Microsoft Office SharePoint Server 2007 SP1, SP2 (64-bit editions) o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Office Converter Pack - Works 8.5 - Works 9
¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-021.mspx
[MS09-022] Windows Print Spooler Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o »ç¿ëÀÚ ½Ã½ºÅÛ¿¡¼ °ø°ÝÀÚ°¡ Àü¼ÛÇÑ Á¶ÀÛµÈ RPC ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå ½ÇÇàÃë¾àÁ¡ Á¸Àç ¡Ø RPC : Remote Procedure Call, ¾î¶² ÇÁ·Î±×·¥ÀÌ ³×Æ®¿öÅ©»óÀÇ ´Ù¸¥ ½Ã½ºÅÛ¿¡ À§Ä¡ÇÏ°í ÀÖ´Â ÇÁ·Î±×·¥¿¡ ¼ºñ½º¸¦ ¿äûÇÒ ¶§ »ç¿ëµÇ´Â ¼ºñ½º o Ãë¾àÁ¡ °ø°Ý ½Ã °ø°ÝÀÚ´Â ¼¹ö ¼ºñ½º°¡ µ¿ÀÛÁßÀÎ ÄÄÇ»ÅÍ¿¡ Á¶ÀÛµÈ ³×Æ®¿öÅ© ¸Þ½ÃÁö¸¦ Àü¼Û. °ø°ÝÀÌ ¼º°øÇÏ¸é °ø°ÝÀÚ´Â ÇÁ·Î±×·¥ ¼³Ä¡, »èÁ¦, °èÁ¤ »ý¼º µî ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ °¡´É o °ü·ÃÃë¾àÁ¡ : - Buffer Overflow in Print Spooler Vulnerability - CVE-2009-0228 - Print Spooler Read File Vulnerability - CVE-2009-0229 - Print Spooler Load Library Vulnerability - CVE-2009-0230 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Windows 2000 Server SP4 - Windows XP Professional SP2, SP3 - Windows XP Professional x64 Edition SP2 - Windows Server 2003 SP2 - Windows Server 2003 x64 Edition SP2 - Windows Server 2003 SP2 for Itanium-based Systems - Windows Vista, SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 - Windows Server 2008 for Itanium-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-022.mspx
[MS09-023] Windows Search Ãë¾àÁ¡À¸·Î ÀÎÇÑ Á¤º¸À¯Ãâ ¹®Á¦Á¡ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛÀÇ Á¤º¸ À¯Ãâ °¡´É ¡à ¼³¸í o Windows Search 4.0ÀÇ ÆÄÀÏ ¹Ì¸®º¸±â°¡ º¸¿©Áö´Â ¹æ½ÄÀÇ ¹®Á¦·Î ÀÎÇØ ¹ß»ýÇÏ´Â Á¤º¸ À¯Ãâ ¹®Á¦Á¡ ¡Ø Windows Search: ÄÄÇ»ÅÍ¿¡ ÀÖ´Â ¹®¼, ÀüÀÚ ¸ÞÀÏ ¸Þ½ÃÁö, À½¾Ç ÆÄÀÏ, »çÁø µîÀ» ã°í ¹Ì¸® º¼ ¼ö ÀÖµµ·Ï µµ¿ÍÁÖ´Â µµ±¸ o ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ ÆÄÀÏÀÌ °Ë»ö °á°ú·Î º¸¿©Áú °æ¿ì, ÇØ´ç ÆÄÀÏÀÇ HTML ½ºÅ©¸³Æ®°¡ ½ÇÇàµÇ¸é¼ Á¤º¸°¡ À¯ÃâµÉ ¼ö ÀÖÀ½ o °ü·ÃÃë¾àÁ¡ : - Script Execution in Windows Search Vulnerability - CVE-2009-0239 o ¿µÇâ : Á¤º¸À¯Ãâ o Áß¿äµµ : º¸Åë ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Windows Search 4.0 on Windows XP SP2, SP3 - Windows Search 4.0 on Windows XP Professional x64 Edition SP2 - Windows Search 4.0 on Windows Server 2003 SP2 - Windows Search 4.0 on Windows Server 2003 x64 Edition SP2 o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Windows Vista, SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-023.mspx
[MS09-024] Microsoft Works º¯È¯±â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦Á¡ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o Microsoft Works º¯È¯±â°¡ Works(.WPS) ÆÄÀÏÀ» ó¸®ÇÏ´Â °úÁ¤¿¡ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ÀÌ Á¸Àç ¡Ø Microsoft Works: Microsoft Office¿¡ Æ÷ÇÔµÈ ¹®¼ ÀúÀÛ µµ±¸·Î¼ ±¹³»¿¡¼´Â Ãâ½ÃµÇÁö ¾Ê¾ÒÀ½ o °ø°ÝÀڴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ Works ÆÄÀÏÀ» ¿µµ·Ï À¯µµÇÏ¿© ÇØ´ç »ç¿ëÀÚ ±ÇÇÑÀ» ȹµæ °¡´É o °ü·ÃÃë¾àÁ¡ : - File Converter Buffer Overflow Vulnerability - CVE-2009-1533 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Office Word 2000 SP3 - Microsoft Office Word 2002 SP3 - Microsoft Office Word 2003 SP3 with the Microsoft Works 6–9 File Converter - Microsoft Office Word 2007 SP1 - Microsoft Works 8.5 - Microsoft Works 9 o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Office 2007 SP2 - Microsoft Office 2004 for Mac - Microsoft Office 2008 for Mac - Open XML File Format Converter for Mac - Microsoft Office Word Viewer 2003 SP3 - Microsoft Office Word Viewer SP1, SP2 - Microsoft Office Compatibility Pack SP1, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-024.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-024.mspx [MS09-025] À©µµ¿ì Ä¿³Î Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦Á¡ ¡à ¿µÇâ o »ç¿ëÀÚ ±ÇÇÑÀ» °¡Áø °ø°ÝÀÚ´Â Ä¿³Î ¸ðµå¿¡¼ ÀÓÀÇÀÇ ÄÚµå ½ÇÇà °¡´ÉÇÔ ¡à ¼³¸í o À©µµ¿ì Ä¿³ÎÀÌ Æ¯Á¤ Ä¿³Î °´Ã¼ÀÇ º¯È¸¦ ÀûÀýÇÏ°Ô °ËÁõÇÏÁö ¸øÇϰųª, À©µµ¿ì Ä¿³Î ½Ã½ºÅÛ È£Ãâ·Î Àü´Þ µÇ´Â Àμö ¹× À¯Àú¸ðµå·ÎºÎÅÍ Àü´ÞµÈ Æ÷ÀÎÅÍ, ÀԷ°ªÀ» °ËÁõÀÌ ºÒÃæºÐÇÏ¿© ¹ß»ýÇÏ´Â ±ÇÇÑ»ó½Â Ãë¾àÁ¡ o °ø°ÝÀÌ ¼º°øÇÒ °æ¿ì °ø°ÝÀÚ´Â Ä¿³Î ¸ðµå¿¡¼ ÀÓÀÇÀÇ ÄÚµå ½ÇÇà °¡´ÉÇÔ o °ü·ÃÃë¾àÁ¡ : - Windows Kernel Desktop Vulnerability- CVE-2009-1123 - Windows Kernel Pointer Validation Vulnerability- CVE-2009-1124 - Windows Driver Class Registration Vulnerability - CVE-2009-1125 - Windows Desktop Parameter Edit Vulnerability - CVE-2009-1126 o ¿µÇâ : ±ÇÇÑ»ó½Â o Áß¿äµµ : Áß¿ä ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Windows 2000 SP4 - Windows XP SP2, SP3 - Windows XP Professional x64 Edition SP2 - Windows Server 2003 SP2 - Windows Server 2003 x64 Edition SP2 - Windows Server 2003 for Itanium-based Systems SP2 - Windows Vista, SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 - Windows Server 2008 for Itanium-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-025.mspx
[MS09-026] RPC Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ»ó½Â ¹®Á¦Á¡ ¡à ¿µÇâ o ±ÇÇÑ»ó½Â °ø°ÝÀ» ¼º°øÇÑ °ø°ÝÀÚ´Â ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o À©µµ¿ì RPC Marshalling EngineÀÌ ³»ºÎ »óÅ Á¤º¸ÀÇ °»½ÅÀÌ ÀûÀýÇÏÁö ¾Ê°Ô ÀÌ·ç¾îÁüÀ¸·Î ÀÎÇؼ ±ÇÇÑ»ó½Â Ãë¾àÁ¡ÀÌ ¹ß»ý ¡Ø RPC(Remote Procedure Call) : ¾î¶² ÇÁ·Î±×·¥ÀÌ ³×Æ®¿öÅ©»óÀÇ ´Ù¸¥ ½Ã½ºÅÛ¿¡ À§Ä¡ÇÏ°í ÀÖ´Â ÇÁ·Î±×·¥¿¡ ¼ºñ½º¸¦ ¿äûÇÒ ¶§ »ç¿ëµÇ´Â ¼ºñ½º o °ø°ÝÀÌ ¼º°øÇÒ °æ¿ì °ø°ÝÀÚ´Â ¿µÇâ¹Þ´Â ½Ã½ºÅÛ¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÏ°í ¿ÏÀüÇÑ ±ÇÇÑÀ» ȹµæ °¡´É o °ü·ÃÃë¾àÁ¡ : - RPC Marshalling Engine Vulnerability - CVE-2009-0568 o ¿µÇâ : ±ÇÇÑ»ó½Â o Áß¿äµµ : Áß¿ä ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Windows 2000 SP4 - Windows XP SP2, SP3 - Windows XP Professional x64 Edition SP2 - Windows Server 2003 SP2 - Windows Server 2003 x64 Edition SP2 - Windows Server 2003 for Itanium-based Systems SP2 - Windows Vista, SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 - Windows Server 2008 for Itanium-based Systems, SP2 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-026.mspx
[MS09-027] Microsoft Office Word Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÄÚµå½ÇÇà ¹®Á¦Á¡ ¡à ¿µÇâ o °ø°ÝÀÚ°¡ ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑ È¹µæ ¡à ¼³¸í o Microsoft Office Word°¡ ºñÁ¤»óÀûÀÎ ·¹Äڵ带 Æ÷ÇÔÇÑ ¿öµå ÆÄÀÏÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ÀÌ Á¸Àç o °ø°ÝÀÌ ¼º°øÇÒ °æ¿ì °ø°ÝÀÚ´Â ¿µÇâ¹Þ´Â ½Ã½ºÅÛÀÇ ¿ÏÀüÇÑ ±ÇÇÑÀ» ȹµæ °¡´É o °ü·ÃÃë¾àÁ¡ : - Word Buffer Overflow Vulnerability - CVE-2009-0563 - Word Buffer Overflow Vulnerability - CVE-2009-0565 o ¿µÇâ : ¿ø°ÝÄÚµå½ÇÇà o Áß¿äµµ : ±ä±Þ ¡à ÇØ´ç½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Office Word 2000 SP3 - Microsoft Office Word 2002 SP3 - Microsoft Office Word 2003 SP3 - Microsoft Office Word 2007 SP1, SP2 - Microsoft Office 2004 for Mac - Microsoft Office 2008 for Mac - Open XML File Format Converter for Mac - Microsoft Office Word Viewer 2003 SP3 - Microsoft Office Word Viewer - Microsoft Office Compatibility Pack SP1, SP2 o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î - Microsoft Works 8.5 - Microsoft Works 9 ¡à ÇØ°áÃ¥ o ÇØ´ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë ¡à ÂüÁ¶»çÀÌÆ® o ¿µ¹® : http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx o ÇÑ±Û : http://www.microsoft.com/korea/technet/security/bulletin/MS09-027.mspx
|
|