Security Bulletin MS05-014¿¡ Æ÷ÇÔµÈ º¸¾È ¾÷µ¥ÀÌÆ® 867282¸¦ ¼³Ä¡ÇÑ ÈÄ <input type=image> ű׸¦ »ç¿ëÇÏ´Â À¥ »çÀÌÆ®¿¡¼­ À̹ÌÁö¸¦ º¹»çÇϸé Internet Explorer°¡ ÀÛµ¿ÇÏÁö ¾Ê´Â´Ù

±â¼ú ÀÚ·á: 894926 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

Çö»ó

Microsoft Security Bulletin MS05-014¿¡ Æ÷ÇÔµÈ º¸¾È ¾÷µ¥ÀÌÆ® 867282¸¦ ¼³Ä¡ÇÑ ÈÄ <input type=image> ű׸¦ »ç¿ëÇÏ´Â À¥ »çÀÌÆ®¿¡¼­ À̹ÌÁö¸¦ º¹»çÇϸé Microsoft Internet Explorer°¡ ÀÛµ¿ÇÏÁö ¾Ê½À´Ï´Ù.

¿øÀÎ

À̹ÌÁö¿Í ºñ½ÁÇÑ Microsoft Excel ½ºÇÁ·¹µå½ÃÆ®¸¦ ¹ÙÅÁ È­¸éÀ¸·Î ²ø¾î¼­ ³õ´Â ¾ÇÀÇÀûÀΠƯÁ¤ ½Ã³ª¸®¿À¸¦ Â÷´ÜÇϵµ·Ï ÇÏ´Â º¯°æ ³»¿ëÀÌ º¸¾È ¾÷µ¥ÀÌÆ® 867282¿¡ Ãß°¡µÇ¾ú½À´Ï´Ù. ÀÌ ½Ã³ª¸®¿À¸¦ Â÷´ÜÇϵµ·Ï º¯°æµÈ ÄÚµå´Â ²ø¾î¼­ ³õ±â ÀÛ¾÷°ú À̹ÌÁö º¹»ç ÀÛ¾÷¿¡ »ç¿ëµË´Ï´Ù. ÀÌ·¯ÇÑ º¯°æÀ¸·Î ÀÎÇØ <input type=image> ű׿¡¼­ À̹ÌÁö¸¦ º¹»çÇÒ ¶§ ³í¸® ¿À·ù°¡ ¹ß»ýÇÏ¿© Internet Explorer°¡ ÀÛµ¿ÇÏÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù.

ÇØ°á ¹æ¹ý

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é º¸¾È ¾÷µ¥ÀÌÆ® 890923(MS05-020)À» ¼³Ä¡ÇϽʽÿÀ. º¸¾È ¾÷µ¥ÀÌÆ® 890923¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
890923 MS05-020: Internet Explorer ´©Àû º¸¾È ¾÷µ¥ÀÌÆ®

ÇØ°á °úÁ¤

À¥ °³¹ßÀÚ¸¦ À§ÇÑ ¹®Á¦ ÇØ°á


<input type=image> ű׸¦ »ç¿ëÇÏ´Â »çÀÌÆ®°¡ ÀÖÀ» °æ¿ì ´ÙÀ½À» ¼öÇàÇÏ¿© ÀÌ ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • À̹ÌÁö¸¦ Ç¥½ÃÇÏ·Á¸é À̹ÌÁö¸¦ ÁöÁ¤ÇÏ´Â À¯Çü Ư¼ºÀÌ Æ÷ÇÔµÈ ÀÔ·Â ¿ä¼Ò ´ë½Å img ¿ä¼Ò(¿¹: <img src=¡±sample.gif¡±>)¸¦ »ç¿ëÇϽʽÿÀ.
  • »ç¿ëÀÚ°¡ ´©¸¥ À̹ÌÁö ÁÂÇ¥´Â <img> ¿ä¼Ò¿Í <onclick> 󸮱⸦ »ç¿ëÇÏ¿© ÁÂÇ¥¸¦ ĸóÇϰí <input type=submit> ÄÁÆ®·ÑÀ» ÅëÇØ Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î ´ÙÀ½ Äڵ带 »ç¿ëÇϽʽÿÀ.
    <script>
    function ClickHandler(e)
    {
     document.all.form1.imgx.value = e.offsetX;
     document.all.form1.imgy.value = e.offsetY;
     document.all.form1.submit();
    }
    </script>
    <form action="form.asp" method="post" id=form1 name=form1>
    <input type=hidden name="imgobj.x" id=imgx value=0>
    <input type=hidden name="imgobj.y" id=imgy value=0>
    <img src=someimage.jpg onclick="ClickHandler(event);">
    </form>
ÀÌ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ ¼ÒÇÁÆ®¿þ¾î ¾÷µ¥ÀÌÆ®¸¦ Áغñ ÁßÀÔ´Ï´Ù. ÀÌ ¾÷µ¥ÀÌÆ®´Â ´ÙÀ½ Internet Explorer º¸¾È ¾÷µ¥ÀÌÆ®¿¡ Æ÷Ç﵃ ¿¹Á¤ÀÔ´Ï´Ù.

À¥ »ç¿ëÀÚ¸¦ À§ÇÑ ¹®Á¦ ÇØ°á

ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇϽʽÿÀ.
  1. <input type=image> ű׸¦ »ç¿ëÇÏ´Â À̹ÌÁö¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ´ÙÀ½ ´Ù¸¥ À̸§À¸·Î ±×¸² ÀúÀåÀ» ´­·¯ À̹ÌÁö ÆÄÀÏÀ» ¹ÙÅÁ È­¸é¿¡ ÀúÀåÇÕ´Ï´Ù.
  2. ½ÃÀÛ, ½ÇÇàÀ» Â÷·Ê·Î ´©¸£°í ¿­±â »óÀÚ¿¡ mspaint¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
  3. ±×¸²ÆÇÀÇ ÆÄÀÏ ¸Þ´º¿¡¼­ ¿­±â¸¦ ´©¸¨´Ï´Ù.
  4. ¹ÙÅÁ È­¸é¿¡ ÀúÀåÇÑ À̹ÌÁö ÆÄÀÏÀ» Ŭ¸¯ÇÏ¿© ¼±ÅÃÇÑ ´ÙÀ½ ¿­±â¸¦ ´©¸¨´Ï´Ù.
  5. ÆíÁý ¸Þ´º¿¡¼­ Àüü ¼±ÅÃÀ» ´­·¯ À̹ÌÁö¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  6. ÆíÁý ¸Þ´º¿¡¼­ º¹»ç¸¦ ´©¸¨´Ï´Ù.
ÀÌÁ¦ À̹ÌÁö¸¦ ´Ù¸¥ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ºÙ¿© ³ÖÀ» ¼ö ÀÖ½À´Ï´Ù.

ÂüÁ¶

MS05-014¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
867282 MS05-014: Internet Explorer ´©Àû º¸¾È ¾÷µ¥ÀÌÆ®




Microsoft Á¦Ç° °ü·Ã ±â¼ú Àü¹®°¡µé°ú ¿Â¶óÀÎÀ¸·Î Á¤º¸¸¦ ±³È¯ÇϽ÷Á¸é Microsoft ´º½º ±×·ì¿¡ Âü¿©ÇϽñ⠹ٶø´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 894926 - ¸¶Áö¸· °ËÅä: 2005³â 7¿ù 11ÀÏ ¿ù¿äÀÏ - ¼öÁ¤: 5.3
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft Internet Explorer 5.01 SP4
  • Microsoft Internet Explorer 5.01 ¼­ºñ½º ÆÑ 3
  • Microsoft Internet Explorer 5.5
  • Microsoft Internet Explorer 6.0 ¼­ºñ½º ÆÑ 1
  • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  • Microsoft Windows Server 2003, Web Edition
  • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
  • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 3
  • Microsoft Windows 2000 Professional Edition
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 3
  • Microsoft Windows 2000 ¼­ºñ½º ÆÑ 4
  • Microsoft Windows XP Home Edition
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Professional 64-Bit Edition (Itanium)
Ű¿öµå:?
kberrmsg kbtshoot kbcodesnippet kbappdev kbsecurity kbprb kbcode kbadmin kbexpertiseadvanced kbexpertiseinter KB894926

Çǵå¹é º¸³»±â