Ãë¾àÁ¡ID |
12039 |
À§Çèµµ |
40 |
Æ÷Æ® |
111 |
ÇÁ·ÎÅäÄÝ |
TCP,UDP |
ºÐ·ù |
RPC |
»ó¼¼¼³¸í |
ÇØ´ç SunRPC portmap ¼ºñ½º´Â XDR ¶óÀ̺귯¸®¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. XDR (external data representation) ¶óÀ̺귯¸®µéÀº ³×Æ®¿öÅ© Á¢¼ÓÀ» ÅëÇØ ÇϳªÀÇ ½Ã½ºÅÛ ÇÁ·Î¼¼½º¿¡¼ºÎÅÍ ´Ù¸¥ ½Ã½ºÅÛÀÇ ÇÁ·Î¼¼½º¿¡°Ô µ¥ÀÌÅ͸¦ º¸³»±â À§ÇÑ À̱âÁ¾°£ÀÇ ¼ö´ÜµéÀ» Á¦°øÇÑ´Ù. ÀÌ·¯ÇÑ ·çƾµéÀº ¿©·¯ À̱âÁ¾ ½Ã½ºÅ۵鰣ÀÇ È£È¯À» À§ÇØ °øÅëÀûÀÎ ÀÎÅÍÆäÀ̽ºµéÀ» »ç¿ëÇÒ Çʿ䰡 ÀÖ´Â ¾îÇø®ÄÉÀÌ¼Ç ÇÁ·Î±×·¡¸Óµé¿¡°Ô Åõ¸í¼ºÀ» Á¦°øÇϱâ À§ÇØ RPC (remote procedure call) ±¸Çöµé¿¡¼ °øÅëÀûÀ¸·Î »ç¿ëµÈ´Ù. Sun Microsystems XDR ¶óÀ̺귯¸®ÀÇ ÇÑ ºÎºÐÀ¸·Î ¹èÆ÷µÈ xdrmem_getbytes() ÇÔ¼ö¿¡´Â Integer ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù. ÀÌ ¿À¹öÇ÷οì´Â ´Ù¼öÀÇ ¾îÇø®ÄÉÀ̼ǵ鿡 µµ¿ë°¡´ÉÇÑ ¹öÆÛ ¿À¹öÇ÷οìµéÀ» ¾ß±âÇÒ ¼ö ÀÖÀ¸¸ç ÀÌ´Â ÀÓÀÇÀÇ ÄÚµåÀÇ ½ÇÇà±îÁö À̾îÁú ¼ö ÀÖ´Ù. SunRPC¿¡¼ ÆÄ»ýµÈ XDR ¶óÀ̺귯¸®µéÀÌ ´Ù¾çÇÑ ¾îÇø®ÄÉÀ̼ǵ鿡¼ ´Ù¾çÇÑ º¥´õµé¿¡ ÀÇÇØ »ç¿ëµÇ°í Àֱ⠶§¹®¿¡, ÀÌ °áÇÔÀº ¸¹Àº º¸¾È ¹®Á¦Á¡À» ¾ß±âÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡ÀÇ µµ¿ëÀº ¼ºñ½º °ÅºÎ, ÀÓÀÇÀÇ ÄÚµå ½ÇÇà, ȤÀº Áß¿äÇÑ Á¤º¸ÀÇ ³ëÃâ±îÁö °¡´ÉÇÏ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ rpcbind ¼ºñ½º¸¦ Å©·¡½¬ ½ÃÄ×À» ¼ö ÀÖ´Ù. µû¶ó¼ ¼ºñ½ºÀÇ Á¤»óÀûÀÎ ±â´É ȸº¹À» À§Çؼ´Â Àç½ÃÀÛ ½ÃÄÑ¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2003-10.html http://www.kb.cert.org/vuls/id/516825 http://www.securityfocus.com/archive/1/315599 http://www.securitytracker.com/alerts/2003/Mar/1006295.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sun Microsystems Network Services Library (libnsl) BSD-derived libraries with XDR/RPC routines (libc) GNU C library with sunrpc (glibc) Solaris 2.6, 7, 8 ±×¸®°í 9 AIX 4.3.3, 5.1.0 ±×¸®°í 5.2.0 Linux ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
ÆÐÄ¡°¡ Àû¿ëµÉ ¶§±îÁö ¹Ýµå½Ã ÇÊ¿äÇÏÁö ¾ÊÀº rpcbind¸¦ Æ÷ÇÔÇÑ ¸ðµç RPC ¼ºñ½ºµéÀ» ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù.
-- ȤÀº --
Sun SolarisÀÇ °æ¿ì: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾Æ·¡ÀÇ ÆÐÄ¡¸¦ ½Ã½ºÅÛ¿¡ ¸Â°Ô ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à Oracle»ç¿¡¼ Áö¿øÇÏ´Â Solaris ½Ã½ºÅÛÀÌ¸é ´ÙÀ½ »çÀÌÆ®¿¡¼ ÆÐÄ¡¸¦ ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Ù. http://support.oracle.com
SPARC: Solaris 2.6: T105401-44 or later Solaris 7: T106942-27 or later Solaris 8: T108993-18 or later Solaris 9: T113319-11 or later
x86: Solaris 2.6: T105402-44 or later Solaris 7: T106943-27 or later Solaris 8: T108994-18 or later Solaris 9: T113719-04 or later
IBM AIXÀÇ °æ¿ì: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
AIX 4.3.3 APAR ¹øÈ£: IY38524 AIX 5.1.0 APAR ¹øÈ£: IY38434 AIX 5.2.0 APAR ¹øÈ£: IY39231
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT º¸¾È ±Ç°í¾È CA-2003-10À» ÂüÁ¶ÇÑ´Ù: http://www.cert.org/advisories/CA-2003-10.html |
°ü·Ã URL |
CVE-2003-0028 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
11563 (ISS) |
|