English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12045
À§Çèµµ 40
Æ÷Æ®
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç rpc.mountd µ¥¸óÀº off-by-one ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Linux NFS utils ÆÐŰÁöÀÎ nfs-utils´Â Linux ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¸¦ À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ NFS (Network File System) À¯Æ¿¸®Æ¼ÀÌ´Ù. 1.0.4 ÀÌÀüÀÇ nfs-utils ¹öÀüµéÀº ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇѵ¥ ÀÌ´Â ¿äûµéÀÇ ·Î±ëÀ» ó¸®ÇÏ´Â moundÀÇ xlog ÇÔ¼ö¿¡ ÀÖ´Â off-by-one ¿¡·¯(ÇÑ ¹ÙÀÌÆ® ¿À¹öÇ÷οì)¿¡¼­ ±âÀÎÇÑ´Ù. ÀÌ ¹®Á¦´Â mountd¸¦ ÅëÇØ µµ¿ë °¡´ÉÇÏ´Ù.
¿ø°ÝÁö ȤÀº ·ÎÄÃÀÇ °ø°ÝÀÚ´Â rpc.mountd µ¥¸óÀ¸·Î Àß Á¶ÀÛµÈ RPC (Remote Procedure Call) ¿äûÀ» º¸³» ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í µ¥¸óÀÌ Å©·¡½¬°¡ ¹ß»ýÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â mountdÀÇ ±ÇÇÑÀÎ rootÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Â °¡´É¼ºÀ» °¡Áö°í ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°Ë¿¡ ÀÇÇØ rpc.mountd µ¥¸óÀÌ Å©·¡½¬ µÇ¾úÀ» °ÍÀÌ´Ù. µû¶ó¼­ Á¤»óÀûÀÎ ±â´É ȸº¹À» À§Çؼ­´Â rpc.mountd ¼­ºñ½ºÀÇ Àç½ÃÀÛÀÌ ÇÊ¿äÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/328946
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.html
http://marc.theaimsgroup.com/?l=bugtraq&m=105820223707191&w=2
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux NFS utils package (nfs-utils) 1.0.4 ÀÌÀü ¹öÀüµé
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Linux NFS °³¹ß À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© nfs-utilsÀÇ °¡Àå ÃֽйöÀü(1.0.4 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/nfs/

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Linux º¸¾È ±Ç°í¾È RHSA-2003:206-05À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ nfs-utils ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://rhn.redhat.com/errata/RHSA-2003-206.html

Debian GNU/Linux 3.0 (º°Äª woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA 349-1À» ÂüÁ¶ÇÏ¿© nfs-utilsÀÇ °¡Àå ÃֽŠÆÐŰÁö(nfs-utils_1.0-2woody1 ÀÌ»ó)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://archives.neohapsis.com/archives/bugtraq/2003-07/0169.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È ±Ç°í¾È SuSE-SA:2003:031À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ nfs-utils ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/

±âŸ ¹èÆ÷ÆÇ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0252 (CVE)
°ü·Ã URL 8179 (SecurityFocus)
°ü·Ã URL 12600 (ISS)