Ãë¾àÁ¡ID |
12052 |
À§Çèµµ |
40 |
Æ÷Æ® |
|
ÇÁ·ÎÅäÄÝ |
ICMP |
ºÐ·ù |
Protocol |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛÀº À߸øµÈ Fragment ÆÐŶµéÀ» ÀÌ¿ëÇÑ Flooding °ø°Ý¿¡ ÀÇÇØ Å©·¡½¬µÈ °ÍÀ¸·Î ³ªÅ¸³´Ù. À̰ÍÀº 'jolt2' ¼ºñ½º °ÅºÎ °ø°ÝÀ¸·Î ¾Ë·ÁÁ® ÀÖ´Ù. ƯÈ÷, Check Point »çÀÇ FireWall-1 ¹öÀü 1.4.0°ú 1.4.1Àº ÆÐŶ Fragmentation ¼ºñ½º °ÅºÎ¿¡ Ãë¾àÇÏ´Ù. Check Point FireWall-1·Î Á÷Á¢ ȤÀº ¶ó¿ìÆ® µÇ´Â ºñÁ¤»óÀûÀÎ FragmentµÈ ÆÐŶµéÀ» º¸³¿À¸·Î½á, ¹æÈº®ÀÌ ÀÌ ÆÐŶµéÀ» ·Î±ëÇÏ´Â °¡¿ë ÇÁ·Î¼¼¼ ½Ã°£À» 100% ¼Ò¸ðÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. FireWall-1ÀÇ Rule ±â¹ÝÀÇ Á¶Ä¡¹æ¹ýÀ¸·Îµµ ÀÌ °ø°ÝÀ» ¸·¾Æ ³»Áö´Â ¸øÇÏ¸ç ¹æÈº® ·Î±×¿¡µµ ·Î±ëÀÌ µÇÁö ¾Ê´Â´Ù.
* ¾Ë¸²: ÀÌ Á¡°Ë¿¡ ÀÇÇØ ´ë»ó ½Ã½ºÅÛÀ¸·ÎÀÇ ³×Æ®¿öÅ© °æ·Î »ó¿¡ ÀÖ´Â ¶ó¿ìÅ͵鵵 ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2000-05/0473.html http://www.kb.cert.org/vuls/id/35958
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Check Point Firewalls Any version |
ÇØ°áÃ¥ |
Check Point Firewall°ú VPNÀÇ °æ¿ì: Check Point´Â ´õ ÀÌ»ó ÀÌ ¸ðµ¨À» Áö¿øÇÏÁö ¾Ê´Â´Ù. º¥´õ¿¡ ¹®ÀÇÇÏ¿© °¡Àå ÃÖ½ÅÀÇ ¼ºñ½º ÆÑ ȤÀº Hotfix¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î FireWall-1ÀÇ ¸ðµâ(µé)¿¡¼ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÏ¿© ÄÜ¼Ö ·Î±ëÀ» ÀÛµ¿ÁßÁö ½ÃŲ´Ù:
$FWDIR/bin/fw ctl debug -buf
ÀÌ ¸í·ÉÀÌ ¹æÈº® ¼ÒÇÁÆ®¿þ¾î°¡ Àç½ÃÀÛµÉ ¶§¸¶´Ù ÀÛµ¿µÇµµ·Ï Çϱâ À§Çؼ´Â $FWDIR/bin/fw/fwstart ¸í·É¿¡ Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2000-0482 (CVE) |
°ü·Ã URL |
1312 (SecurityFocus) |
°ü·Ã URL |
4609 (ISS) |
|