Á¦¸ñ 2009³â 10¿ù ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °øÁö
2009³â 10¿ù 15ÀÏ (¸ñ)¿¡ ¹ßÇ¥µÈ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °øÁö ¹ßÇ¥ ³»¿ëÀ» ¿ä¾àÇÏ¿© Á¦°øÇÕ´Ï´Ù. º¸¾È °øÁö´Â ¿ù ´ÜÀ§·Î ¹ßÇ¥µÇ¾î º¸¾È Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

================================================
½Å±Ô º¸¾È °øÁö
================================================

¸¶ÀÌÅ©·Î¼ÒÇÁÆ®´Â »õ·Î ¹ß°ßµÈ Ãë¾àÁ¡¿¡ ´ëÇÏ¿© ´ÙÀ½°ú °°ÀÌ 13°³ÀÇ ½Å±Ô º¸¾È °øÁö¸¦ ¹ßÇ¥ÇÕ´Ï´Ù.

MS09-050 (±ä±Þ) Windows Vista, Windows Server 2008
MS09-051 (±ä±Þ) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008
MS09-052 (±ä±Þ) Windows 2000, Windows XP, Windows Server 2003
MS09-053 (Áß¿ä) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008
MS09-054 (±ä±Þ) Internet Explorer (Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2)
MS09-055 (±ä±Þ) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2
MS09-056 (Áß¿ä) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2
MS09-057 (Áß¿ä) Windows 2000, Windows XP, Windows Server 2003
MS09-058 (Áß¿ä) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008
MS09-059 (Áß¿ä) Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2
MS09-060 (±ä±Þ) Outlook 2002, Outlook 2003, Outlook 2007, Visio Viewer 2002, Visio Viewer 2003, Visio Viewer 2007
MS09-061 (±ä±Þ) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Silverlight 2
MS09-062 (±ä±Þ) Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Office, SQL Server, Visual Studio, Forefront

À§¿¡ ³ª¿­ÇÑ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î ¸ñ·ÏÀº °£´ÜÈ÷ ¿ä¾àÇÑ °ÍÀÔ´Ï´Ù. ¿µÇâÀ» ¹Þ´Â ±¸¼º ¿ä¼Ò Àüü ¸ñ·ÏÀ» º¸·Á¸é °¢ º¸¾È °øÁö¸¦ ¿­°í "¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î" ºÎºÐÀ» »ìÆìº¸½Ã±â ¹Ù¶ø´Ï´Ù.


================================================
½Å±Ô º¸¾È °øÁö ¿ä¾à À¥ ÆäÀÌÁö
================================================

½Å±Ô °øÁö¿¡ ´ëÇÑ ¿ä¾àÀº ´ÙÀ½ ÆäÀÌÁö¿¡ ÀÖ½À´Ï´Ù.
http://www.microsoft.com/korea/technet/security/bulletin/MS09-oct.mspx


================================================
¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸
================================================

¸¶ÀÌÅ©·Î¼ÒÇÁÆ®´Â Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸ÀÇ ¾÷µ¥ÀÌÆ®µÈ ¹öÀüÀ» Windows Server Update Services (WSUS), Windows Update (WU)¿Í ´Ù¿î·Îµå ¼¾ÅÍ¿¡¼­ Á¦°øÇÕ´Ï´Ù.
ÀÌ µµ±¸´Â Software Update Services (SUS)¸¦ ÅëÇØ¼­´Â ¹èÆ÷µÇÁö ¾ÊÀ½À» ÁÖÀÇÇÏ¿© ÁֽʽÿÀ.
Microsoft Windows ¾Ç¼º ¼ÒÇÁÆ®¿þ¾î Á¦°Å µµ±¸¿¡ ´ëÇÑ Á¤º¸´Â http://support.microsoft.com/kb/890830 ¿¡¼­ º¸½Ç ¼ö ÀÖ½À´Ï´Ù.


================================================
º¸¾È ¹®Á¦¿Í °ü°è¾øÁö¸¸ Á߿䵵°¡ ³ôÀº ¾÷µ¥ÀÌÆ®
================================================

¸¶ÀÌÅ©·Î¼ÒÇÁÆ®´Â Microsoft Update (MU), Windows Update (WU), Windows Server Update Services (WSUS)¸¦ ÅëÇØ º¸¾È ¹®Á¦¿Í °ü°è¾øÁö¸¸ Á߿䵵°¡ ³ôÀº ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥ÇÕ´Ï´Ù.
¿À´Ã ¹ßÇ¥ÇÑ Àüü ¾÷µ¥ÀÌÆ®ÀÇ ¸ñ·ÏÀº ´ÙÀ½ ±â¼ú ÀÚ·á¿¡¼­ º¼ ¼ö ÀÖ½À´Ï´Ù.

2009³â¿¡ º¯°æµÈ Software Update Services ¹× Windows Server Update Services ³»¿ë¿¡ ´ëÇÑ ¼³¸í
http://support.microsoft.com/kb/894199


================================================
º¸¾È °øÁö À¥Ä³½ºÆ®
================================================

¸¶ÀÌÅ©·Î¼ÒÇÁÆ®´Â À̹ø °øÁö¿¡ ´ëÇÑ °í°´ Áú¹®¿¡ ´äÇÏ´Â À¥Ä³½ºÆ®¸¦ ÁøÇàÇÕ´Ï´Ù.

Á¦¸ñ: Information about Microsoft October Security Bulletins
ÀϽÃ: 2009³â 10¿ù 15ÀÏ (¸ñ) ¿ÀÀü 3½Ã (Çѱ¹ ½Ã°¢)
URL: http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&EventID=1032407488
ÁÖÀÇ: ¸ðµç ³ª¶ó¿¡¼­ µ¿½Ã¿¡ Âü¿©ÇÒ ¼ö ÀÖ´Â ÁúÀÇ ÀÀ´äÀ̱⠶§¹®¿¡ ¿µ¾î·Î ÁøÇàµË´Ï´Ù.


================================================
º¸¾È °øÁö ±â¼ú ¼¼ºÎ »çÇ×
================================================

¾Æ·¡ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î Ç¥¿¡¼­, ³ª¿­µÇÁö ¾ÊÀº ¼ÒÇÁÆ®¿þ¾î´Â Áö¿ø ±â°£ÀÌ Áö³­ Á¦Ç°ÀÔ´Ï´Ù.
Á¦Ç°°ú ¹öÀü¿¡ ´ëÇÑ Áö¿ø ±â°£À» º¸·Á¸é ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® Áö¿ø ±â°£ ÆäÀÌÁö http://support.microsoft.com/lifecycle/ ¸¦ Âü°íÇÏ¿© ÁֽʽÿÀ.

-------------------------------------------------
º¸¾È °øÁö MS09-050
-------------------------------------------------

Á¦¸ñ: SMBv2ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (975517)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â SMBv2(Server Message Block Version 2)¿¡¼­ ¹ß°ßµÇ¾î °ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 1°Ç°ú ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 2°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
°¡Àå À§ÇèÇÑ Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ ¼­¹ö ¼­ºñ½º¸¦ ½ÇÇàÇÏ´Â ÄÄÇ»ÅͷΠƯ¼öÇÏ°Ô Á¶ÀÛµÈ SMB ÆÐŶÀ» Àü¼ÛÇÒ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â SMBv2 ÆÐŶ ³»ºÎ ÇʵåÀÇ À¯È¿¼ºÀ» ¿Ã¹Ù¸£°Ô °Ë»çÇϰí, SMB°¡ SMB ÆÐŶÀÇ ¸í·É °ªÀ» ó¸®ÇÏ´Â ¹æ½Ä ¹× Ư¼öÇÏ°Ô Á¶ÀÛµÈ SMB ÆÐŶÀÇ ±¸¹®À» ºÐ¼®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows Vista
- Windows Server 2008
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- SMBv2 ¹«ÇÑ ·çÇÁ Ãë¾àÁ¡ (CVE-2009-2526)
- SMBv2 ¸í·É °ª Ãë¾àÁ¡ (CVE-2009-2532)
- SMBv2 Çù»ó Ãë¾àÁ¡ (CVE-2009-3103)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: ¾øÀ½

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-050.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-051
-------------------------------------------------

Á¦¸ñ: Windows Media RuntimeÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (975682)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Windows Media Runtime¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 2°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ ¹Ìµð¾î ÆÄÀÏÀ» ¿­°Å³ª, À¥ »çÀÌÆ® ¶Ç´Â À¥ ÄÜÅÙÃ÷¸¦ Á¦°øÇÏ´Â ÀÀ¿ë ÇÁ·Î±×·¥À¸·ÎºÎÅÍ Æ¯¼öÇÏ°Ô Á¶ÀÛµÈ ½ºÆ®¸®¹Ö ÄÜÅÙÃ÷¸¦ ¹ÞÀ» °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Windows Media RuntimeÀÌ ¾ÐÃàµÈ ¿Àµð¿À ÆÄÀÏ¿¡¼­ ASF ÆÄÀÏÀ» ó¸®ÇÏ°í ±â´ÉÀ» ÃʱâÈ­ÇÏ´Â ¹æ½ÄÀ» º¯°æÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- DirectShow WMA À½¼º ÄÚµ¦
- Windows Media ¿Àµð¿À À½¼º µðÄÚ´õ
- ¿Àµð¿À ¾ÐÃà °ü¸®ÀÚ

- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- Windows Media Runtime À½¼º »ùÇøµ ¼Óµµ Ãë¾àÁ¡ (CVE-2009-0555)
- Windows Media Runtime Èü ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2525)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: °æ¿ì¿¡ µû¶ó ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾øÀ» ¼ö ÀÖ½À´Ï´Ù. ÇÏÁö¸¸ ÇÊ¿äÇÑ ÆÄÀÏÀÌ »ç¿ë ÁßÀ̸é ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ °æ¿ì¿¡´Â ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÑ´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË

´Ï´Ù. ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÒ °¡´É¼ºÀ» ÁÙÀÌ·Á¸é ¿µÇâÀ» ¹ÞÀº ¼­ºñ½º¸¦ ¸ðµÎ ÁßÁöÇÏ°í º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡Çϱâ Àü¿¡ ¿µÇâÀ» ¹ÞÀº ÆÄÀÏÀ» »ç¿ëÇÏ´Â ¸ðµç ÀÀ¿ë ÇÁ·Î±×·¥À» ´ÝÀ¸½Ê½Ã¿À. ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇ϶ó´Â ¸Þ½ÃÁö°¡ ³ªÅ¸³ª´Â ÀÌÀ¯¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ

³»¿ëÀº Microsoft ±â¼ú ÀÚ·á ¹®¼­ 887012¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://support.microsoft.com/kb/887012

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: ¾øÀ½

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-051.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-052
-------------------------------------------------

Á¦¸ñ: Windows Media PlayerÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (974112)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Windows Windows Media PlayerÀÇ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ Windows Media Player 6.4¸¦ »ç¿ëÇÏ¿© Ư¼öÇÏ°Ô Á¶ÀÛµÈ ASF ÆÄÀÏÀ» Àç»ýÇÒ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Windows Media Player 6.4°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ ASF ÆÄÀÏÀ» ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows Media Player 6.4

- Windows 2000
- Windows XP
- Windows Server 2003
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- WMP Èü ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2527)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: °æ¿ì¿¡ µû¶ó ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾øÀ» ¼ö ÀÖ½À´Ï´Ù.
ÇÏÁö¸¸ ÇÊ¿äÇÑ ÆÄÀÏÀÌ »ç¿ë ÁßÀ̸é ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ °æ¿ì¿¡´Â ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÑ´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
´Ù½Ã ½ÃÀÛÇØ¾ß ÇÒ °¡´É¼ºÀ» ÁÙÀÌ·Á¸é ¿µÇâÀ» ¹ÞÀº ¼­ºñ½º¸¦ ¸ðµÎ ÁßÁöÇÏ°í º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡Çϱâ Àü¿¡ ¿µÇâÀ» ¹ÞÀº ÆÄÀÏÀ» »ç¿ëÇÏ´Â ¸ðµç ÀÀ¿ë ÇÁ·Î±×·¥À» ´ÝÀ¸½Ê½Ã¿À.
ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇ϶ó´Â ¸Þ½ÃÁö°¡ ³ªÅ¸³ª´Â ÀÌÀ¯¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·á ¹®¼­ 887012¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://support.microsoft.com/kb/887012

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS08-076

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-052.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-053
-------------------------------------------------

Á¦¸ñ: IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) FTP ¼­ºñ½ºÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (975254)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 5.0, Microsoft IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 5.1,
Microsoft IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 6.0 ¹× Microsoft IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 7.0ÀÇ FTP ¼­ºñ½º¿¡ ´ëÇØ °ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 2°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
IIS 7.0¿¡¼­´Â FTP ¼­ºñ½º 6.0¸¸ ¿µÇâÀ» ¹Þ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ IIS 5.0¿¡¼­ FTP ¼­ºñ½º¸¦ ½ÇÇàÇϰí ÀÖ´Â ½Ã½ºÅÛ¿¡ ¿ø°Ý ÄÚµå ½ÇÇà(RCE)ÀÌ ¹ß»ýÇϰųª
IIS 5.0, IIS 5.1, IIS 6.0 ¶Ç´Â IIS 7.0¿¡¼­ FTP ¼­ºñ½º¸¦ ½ÇÇàÇϰí ÀÖ´Â ½Ã½ºÅÛ¿¡ ¼­ºñ½º °ÅºÎ(DoS)°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â FTP ¼­ºñ½º¿¡¼­ ¸ñ·Ï ÀÛ¾÷À» ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: Áß¿ä

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 5.0
- IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 5.1
- IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 6.0
- IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º) 7.0

- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- IIS FTP ¼­ºñ½º DoS Ãë¾àÁ¡ (CVE-2009-2521)
- IIS FTP ¼­ºñ½º RCE ¹× DoS Ãë¾àÁ¡ (CVE-2009-3023)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà, ¼­ºñ½º °ÅºÎ

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÒ ¼öµµ ÀÖ½À´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: ¾øÀ½

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-053.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-054
-------------------------------------------------

Á¦¸ñ: Internet Explorer ´©Àû º¸¾È ¾÷µ¥ÀÌÆ® (974455)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Internet Explorer¿¡ ´ëÇØ ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 3°Ç°ú °ø°³µÈ Ãë¾àÁ¡ 1°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡µéÀº ¸ðµÎ »ç¿ëÀÚ°¡ Internet Explorer¸¦ »ç¿ëÇÏ¿© Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ º¼ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Internet Explorer°¡ µ¥ÀÌÅÍ ½ºÆ®¸² Çì´õ¸¦ ó¸®Çϰí, Àμö À¯È¿¼ºÀ» °Ë»çÇϰí, ¸Þ¸ð¸®ÀÇ °³Ã¼¸¦ ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Internet Explorer 5.01
- Internet Explorer 6
- Internet Explorer 7
- Internet Explorer 8

- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- µ¥ÀÌÆ® ½ºÆ®¸² Çì´õ ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-1547)
- HTML ±¸¼º ¿ä¼Ò ó¸® Ãë¾àÁ¡ (CVE-2009-2529)
- ÃʱâÈ­µÇÁö ¾ÊÀº ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2530)
- ÃʱâÈ­µÇÁö ¾ÊÀº ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2531)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS09-034

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-054.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-055
-------------------------------------------------

Á¦¸ñ: ActiveX ų(Kill) ºñÆ® ´©Àû º¸¾È ¾÷µ¥ÀÌÆ® (973525)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ÇöÀç ¾Ç¿ëµÇ°í ÀÖ´Â ¿©·¯ ActiveX ÄÁÆ®·Ñ¿¡¼­ °øÅëÀ¸·Î ÇØ´çµÇ´Â ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 1°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
Ãë¾àÇÑ ¹öÀüÀÇ Microsoft ATL(¾×Ƽºê ÅÛÇø´ ¶óÀ̺귯¸®)À» »ç¿ëÇÏ¿© ÄÄÆÄÀÏµÈ ActiveX ÄÁÆ®·Ñ¿¡ ¿µÇâÀ» ÁÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇØ
»ç¿ëÀÚ°¡ Internet Explorer·Î ActiveX ÄÁÆ®·ÑÀ» ÀνºÅϽºÈ­Çϴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ º¼ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
º¸¾È ¾÷µ¥ÀÌÆ®´Â Ãë¾àÇÑ ÄÁÆ®·ÑÀÌ Internet Explorer¿¡¼­ ½ÇÇàµÇÁö ¾Êµµ·Ï ų(Kill) ºñÆ®¸¦ ¼³Á¤ÇÔÀ¸·Î½á Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- ATL COM ÃʱâÈ­ Ãë¾àÁ¡ (CVE-2009-2493)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: °æ¿ì¿¡ µû¶ó ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾øÀ» ¼ö ÀÖ½À´Ï´Ù. ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÏ´Â °æ¿ì¿¡´Â ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÑ´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS09-032

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-055.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-056
-------------------------------------------------

Á¦¸ñ: Windows CryptoAPIÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ½ºÇªÇÎ Çã¿ë ¹®Á¦Á¡ (974571)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft Windows¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 2°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
ÃÖÁ¾ »ç¿ëÀÚ°¡ ÀÎÁõ¿¡ »ç¿ëÇÑ ÀÎÁõ¼­¿¡ °ø°ÝÀÚ°¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â °æ¿ì ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ ½ºÇªÇÎÀÌ Çã¿ëµË´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â null Á¾°áÀÚ°¡ Æ÷ÇÔµÈ ÀÎÁõ¼­ À̸§À» °ÅºÎÇϰí ASN.1 °³Ã¼ ½Äº°ÀÚÀÇ À¯È¿¼ºÀ» ¿Ã¹Ù¸£°Ô °Ë»çÇϵµ·Ï CryptoAPI¸¦ ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: Áß¿ä

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- X.509 ÀÏ¹Ý À̸§ Null À߸² Ãë¾àÁ¡ (CVE-2009-2510)
- X.509 °³Ã¼ ½Äº°ÀÚ Á¤¼ö ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2511)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ½ºÇªÇÎ

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS04-007

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-056.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-057
-------------------------------------------------

Á¦¸ñ: Àε¦½Ì ¼­ºñ½ºÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦ (969059)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Microsoft WindowsÀÇ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ActiveX ±¸¼º ¿ä¼Ò¿¡ ´ëÇÑ È£ÃâÀ» ÅëÇØ Àε¦½Ì ¼­ºñ½º¸¦ ½ÇÇàÇÏ´Â ¾ÇÀÇÀûÀÎ À¥ ÆäÀÌÁö¸¦ ¼³Á¤ÇÒ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ È£ÃâÀº ¾ÇÀÇÀûÀÎ URLÀ» Æ÷ÇÔÇÒ ¼ö ÀÖÀ¸¸ç, Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¿© À¥ ÆäÀÌÁö¸¦ °Ë»öÇÏ´Â »ç¿ëÀÚÀÇ ±ÇÇÑÀ¸·Î Ŭ¶óÀÌ¾ðÆ® ½Ã½ºÅÛ¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ±ÇÇÑÀ» °ø°ÝÀÚ¿¡°Ô ºÎ¿©ÇÕ´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Àε¦½Ì ¼­ºñ½º ActiveX ÄÁÆ®·ÑÀÌ URLÀ» ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: Áß¿ä

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows 2000
- Windows XP
- Windows Server 2003
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- Àε¦½Ì ¼­ºñ½ºÀÇ ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2507)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS06-053

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-057.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-058
-------------------------------------------------

Á¦¸ñ: Windows Ä¿³ÎÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ±ÇÇÑ »ó½Â ¹®Á¦Á¡ (971486)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Windows Ä¿³Î¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ ¿©·¯ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
°¡Àå À§ÇèÇÑ Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ ½Ã½ºÅÛ¿¡ ·Î±×¿ÂÇÏ¿© Ư¼öÇÏ°Ô Á¶ÀÛÇÑ ÀÀ¿ë ÇÁ·Î±×·¥À» ½ÇÇàÇÒ °æ¿ì ±ÇÇÑ »ó½ÂÀ» Çã¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Windows Ä¿³ÎÀÌ 64ºñÆ® °ªÀ» ¿Ã¹Ù¸£°Ô ÀÚ¸£°í, ½ÇÇà ÆÄÀÏ ³»¿¡¼­ µ¥ÀÌÅÍÀÇ À¯È¿¼ºÀ» ¿Ã¹Ù¸£°Ô °Ë»çÇϸç, ¿À·ù »óÅ¿¡¼­ ¿¹¿Ü¸¦ Á¤¸®Çϵµ·Ï ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: Áß¿ä

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- Windows Ä¿³Î Á¤¼ö ¾ð´õÇ÷ΠÃë¾àÁ¡ (CVE-2009-2515)
- Windows Ä¿³Î NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶ Ãë¾àÁ¡ (CVE-2009-2516)
- Windows Ä¿³Î ¿¹¿Ü 󸮱â Ãë¾àÁ¡ (CVE-2009-2517)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ±ÇÇÑ »ó½Â, ¼­ºñ½º °ÅºÎ

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS08-064 ¶Ç´Â MS07-022 (¾Æ·¡ ¸µÅ©¿¡¼­ ¼ÒÇÁÆ®¿þ¾î Á¦Ç°º°·Î È®ÀÎÇϽʽÿÀ)

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-058.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-059
-------------------------------------------------

Á¦¸ñ: ·ÎÄà º¸¾È ±â°ü ÇÏÀ§ ½Ã½ºÅÛ ¼­ºñ½ºÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¼­ºñ½º °ÅºÎ ¹®Á¦Á¡ (975467)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Microsoft WindowsÀÇ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù. NTLM ÀÎÁõ ÇÁ·Î¼¼½º Áß¿¡ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀ¸·Î Á¶ÀÛµÈ ÆÐŶÀ» º¸³¾ °æ¿ì
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ ¼­ºñ½º °ÅºÎ°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ÀÎÁõ ÇÁ·Î¼¼½º¿¡¼­ »ç¿ëµÇ´Â ƯÁ¤ °ª ÁýÇÕ¿¡ ´ëÇÑ Ãß°¡ À¯È¿¼º °Ë»ç¸¦ ±¸ÇöÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: Áß¿ä

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- ·ÎÄà º¸¾È ±â°ü ÇÏÀ§ ½Ã½ºÅÛ ¼­ºñ½º Á¤¼ö ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2524)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¼­ºñ½º °ÅºÎ

½Ã½ºÅÛ Àç½ÃÀÛ: º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ë ÈÄ ½Ã½ºÅÛÀ» Àç½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: ¾øÀ½

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-059.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-060
-------------------------------------------------

Á¦¸ñ: Microsoft Office¿ë Microsoft ATL(¾×Ƽºê ÅÛÇø´ ¶óÀ̺귯¸®) ActiveX ÄÁÆ®·ÑÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (973965)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Ãë¾àÇÑ ¹öÀüÀÇ Microsoft ATL(¾×Ƽºê ÅÛÇø´ ¶óÀ̺귯¸®)À» »ç¿ëÇÏ¿© ÄÄÆÄÀÏµÈ Microsoft Office¿ë ActiveX ÄÁÆ®·Ñ¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ ¿©·¯ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ ±¸¼º ¿ä¼Ò ¶Ç´Â ÄÁÆ®·ÑÀ» ·ÎµåÇÏ´Â °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â ATLÀÌ µ¥ÀÌÅÍ ½ºÆ®¸²¿¡¼­ °³Ã¼ ÀνºÅϽºÈ­¸¦ ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤Çϰí, ¼öÁ¤µÈ ATL Çì´õ¸¦ »ç¿ëÇÏ¿© ÀÛ¼ºµÈ ¿µÇâÀ» ¹Þ´Â ±¸¼º ¿ä¼Ò ¹× ÄÁÆ®·ÑÀÇ ¾÷µ¥ÀÌÆ®µÈ ¹öÀüÀ» Á¦°øÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Outlook 2002
- Outlook 2003
- Outlook 2007
- Visio 2002 Viewer
- Visio 2003 Viewer
- Visio Viewer 2007
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- ATL ÃʱâÈ­µÇÁö ¾ÊÀº °³Ã¼ Ãë¾àÁ¡ (CVE-2009-0901)
- ATL COM ÃʱâÈ­ Ãë¾àÁ¡ (CVE-2009-2493)
- ATL Null ¹®ÀÚ¿­ Ãë¾àÁ¡ (CVE-2009-2495)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà, Á¤º¸ À¯Ãâ

½Ã½ºÅÛ Àç½ÃÀÛ: °æ¿ì¿¡ µû¶ó ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾øÀ» ¼ö ÀÖ½À´Ï´Ù. ÇÏÁö¸¸ ÇÊ¿äÇÑ ÆÄÀÏÀÌ »ç¿ë ÁßÀ̸é ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
ÀÌ·¯ÇÑ °æ¿ì¿¡´Â ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÑ´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù. ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÒ °¡´É¼ºÀ» ÁÙÀÌ·Á¸é ¿µÇâÀ» ¹ÞÀº ¼­ºñ½º¸¦ ¸ðµÎ ÁßÁöÇϰí
º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡Çϱâ Àü¿¡ ¿µÇâÀ» ¹ÞÀº ÆÄÀÏÀ» »ç¿ëÇÏ´Â ¸ðµç ÀÀ¿ë ÇÁ·Î±×·¥À» ´ÝÀ¸½Ê½Ã¿À.
ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇ϶ó´Â ¸Þ½ÃÁö°¡ ³ªÅ¸³ª´Â ÀÌÀ¯¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·á ¹®¼­ 887012¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://support.microsoft.com/kb/887012

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS08-015

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-060.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-061
-------------------------------------------------

Á¦¸ñ: Microsoft .NET °ø¿ë ¾ð¾î ·±Å¸ÀÓÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (974378)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft .NET Framework ¹× Microsoft Silverlight¿¡¼­ ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡ 3°ÇÀ» ÇØ°áÇÕ´Ï´Ù.
»ç¿ëÀÚ°¡ XBAP(XAML ºê¶ó¿ìÀú ÀÀ¿ë ÇÁ·Î±×·¥) ¶Ç´Â Silverlight ÀÀ¿ë ÇÁ·Î±×·¥À» ½ÇÇàÇÒ ¼ö ÀÖ´Â À¥ ºê¶ó¿ìÀú¸¦ »ç¿ëÇÏ¿© Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ º¸°Å³ª,
°ø°ÝÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛÇÑ Microsoft .NET ÀÀ¿ë ÇÁ·Î±×·¥À» ½ÇÇàÇϵµ·Ï »ç¿ëÀÚ¸¦ À¯ÀÎÇÏ´Â µ¥ ¼º°øÇÒ °æ¿ì ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ Ŭ¶óÀÌ¾ðÆ® ½Ã½ºÅÛ¿¡ ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
¼­¹ö¿¡¼­ ASP.NET ÆäÀÌÁö 󸮸¦ Çã¿ëÇÏ°í °ø°ÝÀÚ°¡ ÇØ´ç ¼­¹ö¿¡ Ư¼öÇÏ°Ô Á¶ÀÛÇÑ ASP.NET ÆäÀÌÁö¸¦ ¼º°øÀûÀ¸·Î ¾÷·ÎµåÇÏ¿© ½ÇÇàÇÒ °æ¿ì
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ IIS¸¦ ½ÇÇàÇÏ´Â ¼­¹ö ½Ã½ºÅÛ¿¡ ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ °æ¿ì´Â À¥ È£½ºÆÃ ½Ã³ª¸®¿À¿¡¼­ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.
¾ÇÀÇÀûÀÌÁö ¾ÊÀº Microsoft .NET ÀÀ¿ë ÇÁ·Î±×·¥, Silverlight ÀÀ¿ë ÇÁ·Î±×·¥, XBAP ¹× ASP.NET ÆäÀÌÁö´Â ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀ» ¹ÞÀ» À§ÇèÀÌ ¾ø½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft .NETÀÌ È®ÀÎ °¡´ÉÇÑ ÄÚµå ±ÔÄ¢À» È®ÀÎÇϰí Àû¿ëÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤Çϰí, Microsoft .NET CLR(°ø¿ë ¾ð¾î ·±Å¸ÀÓ)ÀÌ ÀÎÅÍÆäÀ̽º¸¦ ó¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- .NET Framework 1.0
- .NET Framework 1.1
- .NET Framework 2.0
- .NET Framework 3.5

- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Silverlight 2
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- Microsoft .NET Framework Æ÷ÀÎÅÍ È®ÀÎ Ãë¾àÁ¡ (CVE-2009-0090)
- Microsoft .NET Framework Çü½Ä È®ÀÎ Ãë¾àÁ¡ (CVE-2009-0091)
- Microsoft Silverlight ¹× Microsoft .NET Framework CLR Ãë¾àÁ¡ (CVE-2009-2497)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: °æ¿ì¿¡ µû¶ó ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾øÀ» ¼ö ÀÖ½À´Ï´Ù.
ÇÏÁö¸¸ ÇÊ¿äÇÑ ÆÄÀÏÀÌ »ç¿ë ÁßÀ̸é ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ °æ¿ì¿¡´Â ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÑ´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS07-040

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-061.mspx

-------------------------------------------------
º¸¾È °øÁö MS09-062
-------------------------------------------------

Á¦¸ñ: GDI+ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°Ý ÄÚµå ½ÇÇà ¹®Á¦Á¡ (957488)

¿ä¾à: ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft Windows GDI+¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ ¿©·¯ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ »ç¿ëÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÏ¿© Ư¼öÇÏ°Ô Á¶ÀÛµÈ À̹ÌÁö¸¦ º¸°Å³ª Ư¼öÇÏ°Ô Á¶ÀÛµÈ ÄÜÅÙÃ÷°¡ Æ÷ÇÔµÈ À¥»çÀÌÆ®¸¦ Ž»öÇÒ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ Çã¿ëµÉ ¼ö ÀÖ½À´Ï´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â WMF À̹ÌÁö¸¦ ·»´õ¸µÇÒ ¶§ GDI+ ³»¿¡¼­ ÀûÀýÇÑ µ¥ÀÌÅÍ À¯È¿¼º °Ë»ç¸¦ Àû¿ëÇϰí, PNG ÆÄÀÏÀ» ÀÐÀ» ¶§ GDI+°¡ Èü ¹öÆÛ¸¦ °ü¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤Çϰí,
GDI+°¡ TIFF ÆÄÀÏÀ» ÀÐÀ» ¶§ »ç¿ëµÇ´Â ¹öÆÛ¸¦ ÇÒ´çÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤ÇÏ¿© Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù. ¶ÇÇÑ ÀÌ ¾÷µ¥ÀÌÆ®´Â ƯÁ¤ .NET API È£Ã⠽à GDI+°¡ ¹öÆÛ¸¦ °ü¸®ÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤Çϰí,
PNG À̹ÌÁöÀÌ ±¸¹®À» ºÐ¼®ÇÒ ¶§ GDI+°¡ ÇÊ¿äÇÑ ¹öÆÛ Å©±â¸¦ °è»êÇÏ´Â ¹æ½ÄÀ» ¼öÁ¤Çϸç, Microsoft Office°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ ÆÄÀÏÀ» ¿©´Â ¹æ½ÄÀ» ¼öÁ¤ÇÕ´Ï´Ù.

ÃÖ´ë ½É°¢µµ: ±ä±Þ

¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- SQL Server 2000 ¸®Æ÷ÆÃ ¼­ºñ½º
- SQL Server 2005
- Report Viewer 2005
- Report Viewer 2008
- Office XP
- Office 2003
- 2007 Microsoft Office System
- Word, Excel, PowerPoint 2007 ÆÄÀÏ Çü½Ä¿ë Microsoft Office ȣȯ ±â´É ÆÑ
- Expression Web
- Expression Web 2
- Office Groove 2007
- Works 8.5
- Project 2002
- Visio 2002
- Forefront Client Security 1.0
(¾Æ·¡ ¸µÅ©¿¡¼­ ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î¿Í ´Ù¿î·Îµå À§Ä¡¸¦ È®ÀÎÇϽʽÿÀ)

Ãë¾àÁ¡:
- GDI+ WMF Á¤¼ö ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2500)
- GDI+ PNG Èü ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2501)
- GDI+ TIFF ¹öÆÛ ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2502)
- GDI+ TIFF ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2503)
- GDI+ .NET API Ãë¾àÁ¡ (CVE-2009-2504)
- GDI+ PNG Á¤¼ö ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-3126)
- ¸Þ¸ð¸® ¼Õ»ó Ãë¾àÁ¡ (CVE-2009-2528)
- Office BMP Á¤¼ö ¿À¹öÇ÷ΠÃë¾àÁ¡ (CVE-2009-2518)

Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿µÇâ: ¿ø°Ý ÄÚµå ½ÇÇà

½Ã½ºÅÛ Àç½ÃÀÛ: ¾÷µ¥ÀÌÆ®µÇ´Â ´ë»ó Á¦Ç° ¹öÀü¿¡ µû¶ó Àç½ÃÀÛÀÌ ÇÊ¿äÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ¾Æ·¡ ¸µÅ©¿¡¼­ ¹öÀü º°·Î È®ÀÎÇϽʽÿÀ.

À̹ø ¾÷µ¥ÀÌÆ®·Î ´ëüµÇ´Â º¸¾È °øÁö: MS08-052

»ó¼¼ Á¤º¸: http://www.microsoft.com/korea/technet/security/bulletin/MS09-062.mspx

[2009-10-23]