Ãë¾àÁ¡ID |
12045 |
À§Çèµµ |
40 |
Æ÷Æ® |
|
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
RPC |
»ó¼¼¼³¸í |
ÇØ´ç rpc.mountd µ¥¸óÀº off-by-one ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Linux NFS utils ÆÐŰÁöÀÎ nfs-utils´Â Linux ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¸¦ À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ NFS (Network File System) À¯Æ¿¸®Æ¼ÀÌ´Ù. 1.0.4 ÀÌÀüÀÇ nfs-utils ¹öÀüµéÀº ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇѵ¥ ÀÌ´Â ¿äûµéÀÇ ·Î±ëÀ» ó¸®ÇÏ´Â moundÀÇ xlog ÇÔ¼ö¿¡ ÀÖ´Â off-by-one ¿¡·¯(ÇÑ ¹ÙÀÌÆ® ¿À¹öÇ÷οì)¿¡¼ ±âÀÎÇÑ´Ù. ÀÌ ¹®Á¦´Â mountd¸¦ ÅëÇØ µµ¿ë °¡´ÉÇÏ´Ù. ¿ø°ÝÁö ȤÀº ·ÎÄÃÀÇ °ø°ÝÀÚ´Â rpc.mountd µ¥¸óÀ¸·Î Àß Á¶ÀÛµÈ RPC (Remote Procedure Call) ¿äûÀ» º¸³» ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í µ¥¸óÀÌ Å©·¡½¬°¡ ¹ß»ýÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â mountdÀÇ ±ÇÇÑÀÎ rootÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Â °¡´É¼ºÀ» °¡Áö°í ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°Ë¿¡ ÀÇÇØ rpc.mountd µ¥¸óÀÌ Å©·¡½¬ µÇ¾úÀ» °ÍÀÌ´Ù. µû¶ó¼ Á¤»óÀûÀÎ ±â´É ȸº¹À» À§Çؼ´Â rpc.mountd ¼ºñ½ºÀÇ Àç½ÃÀÛÀÌ ÇÊ¿äÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/328946 http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html http://marc.theaimsgroup.com/?l=bugtraq&m=105820223707191&w=2 http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux NFS utils package (nfs-utils) 1.0.4 ÀÌÀü ¹öÀüµé Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Linux NFS °³¹ß À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© nfs-utilsÀÇ °¡Àå ÃֽйöÀü(1.0.4 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/nfs/
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Linux º¸¾È ±Ç°í¾È RHSA-2003:206-05À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ nfs-utils ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://rhn.redhat.com/errata/RHSA-2003-206.html
Debian GNU/Linux 3.0 (º°Äª woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA 349-1À» ÂüÁ¶ÇÏ¿© nfs-utilsÀÇ °¡Àå ÃֽŠÆÐŰÁö(nfs-utils_1.0-2woody1 ÀÌ»ó)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://archives.neohapsis.com/archives/bugtraq/2003-07/0169.html
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE º¸¾È ±Ç°í¾È SuSE-SA:2003:031À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ nfs-utils ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/
±âŸ ¹èÆ÷ÆÇ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0252 (CVE) |
°ü·Ã URL |
8179 (SecurityFocus) |
°ü·Ã URL |
12600 (ISS) |
|