KA-2003-19: Flaw in RPC Endpoint Mapper Could Allow Denial of Service Attacks
-- ÇØ´ç ½Ã½ºÅÛ --------
MS À©µµ¿ìÁî NT 4
MS À©µµ¿ìÁî 2000
MS À©µµ¿ìÁî XP
--¿µÇâ-----------------
RPC ±â¹Ý ¼ºñ½ºÀÇ ¼Õ½Ç·Î ÀÎÇÏ¿© ¼ºñ½º °ÅºÎ °ø°ÝÀ» ´çÇÒ ¼ö ÀÖ´Ù.
* ´Ü, ¿ø°Ý ÄÄÇ»ÅÍÀÇ µ¥ÀÌÅ͸¦ ¸¶À½´ë·Î ¼öÁ¤Çϰųª °Ë»öÇÒ ¼ö´Â ¾øÀ½.
-- ¼³¸í-----------------------------
RPC(¿ø°Ý ÇÁ·Î½ÃÁ® ÄÝ)Àº ÇÑ ÇÁ·Î±×·¥¿¡¼ ³×Æ®¿öÅ©ÀÇ ´Ù¸¥ ÄÄÇ»ÅÍ¿¡ ÀÖ´Â ÇÁ·Î±×·¥ÀÇ ¼ºñ½º¸¦ ¿äûÇÏ´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â ÇÁ·ÎÅäÄÝÀÌ´Ù.
±×·±µ¥, ƯÁ¤ RPC ¼ºñ½º¿¡ ÇÒ´çµÈ Æ÷Æ® ¹øÈ£¸¦ ÆľÇÇÏ´Â ±â´ÉÀ» ¼öÇàÇÏ´Â RPC Á¾Á¡ ¸ÅÆÛ ¼ºñ½º¿¡ °áÇÔÀÌ ¹ß°ßµÇ¾ú´Ù.
°ø°ÝÀº ħÀÔÀÚ°¡ ÀÎÅͳݻ󿡼 RPC ¼ºñ½º°¡ ½ÇÇà(135¹ø Æ÷Æ®)µÇ¾î ÀÖ´Â ÄÄÇ»Å͸¦ ´ë»óÀ¸·Î Á¶ÀÛµÈ RPC ¸Þ½ÃÁö¸¦ º¸³»¾î ½ÃµµÇÑ´Ù.
À̶§ RPC Á¾Á¡ ¸ÅÆÛ ¼ºñ½º¿¡ Á¶ÀÛµÈ RPC ¸Þ½ÃÁö¸¦ ¹ÞÀ¸¸é, À§ °ü·Ã Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¼¹ö¿¡¼ Á¦°øÇÏ´Â RPC ±â¹Ý ¼ºñ½º°¡ ¸ðµÎ ¼Õ½ÇµÇ¾î °á±¹¿¡´Â ¼ºñ½º °ÅºÎ °ø°ÝÀ» ´çÇÒ¼ö ÀÖ´Ù.
ÀÌ¿¡ ´ëÇÑ ±Ùº»ÀûÀÎ ÇØ°áÃ¥Àº °ü·ÃµÈ Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾ÈÆÐÄ¡¸¦ Àû¿ëÇÏ´Â °ÍÀÌ´Ù.
-- ÇØ°áÃ¥--------------------------
1. À©µµ¿ì ½Ã½ºÅÛ¿ë ÆÐÄ¡´Â ´ÙÀ½ ÆÐÄ¡¸¦ ÅëÇØ Á÷Á¢ Àû¿ëÇÏ¸é µÈ´Ù.
* MS À©µµ¿ìÁî 2000
-> //www.microsoft.com/downloads/details.aspx?FamilyId=BD55EB38-A5DE-4810-90F7-097C5B4B9919&displaylang=ko
-> //download.microsoft.com/download/f/e/6/fe6d54cc-1e94-4892-a8c2-1f3e880e31a5/Q331953_W2K_SP4_X86_KO.exe
* À©µµ¿ìÁî XP
32-bit Edition :
-> //download.microsoft.com/download/b/8/6/b865bda1-572c-4590-9b7e-3817ce63d713/Q331953_WXP_SP2_x86_KOR.exe
64-bit edition :
-> //download.microsoft.com/download/9/3/a/93a9fa93-8bd4-463b-8acb-4e4d53b2cb47/Q331953_WXP_SP2_ia64_ENU.exe
2. ÆÐÄ¡ ¼³Ä¡ ÈÄ ÀçºÎÆà ÇÑ´ÙÀ½ ¾Æ·¡¿Í °°ÀÌ È®ÀÎÇÑ´Ù.
* (ÇÑ±Û À©µµ 2000 pro) ¼³Á¤ -> Á¦¾îÆÇ -> ÇÁ·Î±×·¥Ãß°¡/Á¦°Å -> Windows 2000 hotfix(Pre-SP4) Q331953 °¡ Á¸Àç.
* (ÇÑ±Û À©µµ XP) ¼³Á¤ -> Á¦¾îÆÇ-> ÇÁ·Î±×·¥ Ãß°¡/Á¦°Å -> Windows XP (SP1) Q331953 °¡ Á¸Àç.
------- ÂüÁ¶ »çÀÌÆ® --------------------------
//www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-010.asp
//www.microsoft.com/korea/technet/security/bulletin/MS03-010.asp
--------------------------------------------
From. ¨ÏWiNGhoST¢â(winghost@PC»ç¶û)
[ÃÖÁ¾ ¼öÁ¤ ½Ã°£ : 2003³â 3¿ù 27ÀÏ 15½Ã 03ºÐ]