English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12067
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç MailCarrier SMTP ¼­¹ö´Â EHLO ¸í·É¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. MailCarrier´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ ÃÖ½ÅÀÇ º¸¾È°ú ¾ÈƼ½ºÆÔ ±â´ÉµéÀ» °®Ãá ¸ÞÀÏ ¼­¹öÀÌ´Ù. ¶ÇÇÑ ÅØ½ºÆ®·Î µÈ ¸Þ½ÃÁö³ª ÆÐ½º¿öµåÀÇ Àü¼ÛÀ» Çã¿ëÇÏÁö ¾Ê´Â SASL°ú NTLM¿¡ ±â¹ÝÀ» µÐ SSL Åë½Å ¹× SMTP/POP3 ÀÎÁõ ¹æ¹ýµéÀ» Áö¿øÇÑ´Ù. MailCarrier ¹öÀü 2.51Àº EHLO¿Í HELO ¸í·Éµé¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ¸Å¿ì ±ä EHLO ȤÀº HELO ¸í·ÉÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â SMTP ¼­ºñ½º¸¦ Å©·¡½¬ ½ÃŰ°Å³ª ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/11174
http://www.securiteam.com/windowsntfocus/6R0020ABPU.html
http://archives.neohapsis.com/archives/bugtraq/2004-10/0274.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Tabs Labortorties, MailCarrier 2.51
Microsoft Windows Any version
ÇØ°áÃ¥ Tabs Laboratories À¥ »çÀÌÆ®ÀÎ http://www.tabslab.com/ ¿¡¼­ MailCarrier Mail ServerÀÇ °¡Àå ÃֽйöÀü(3.0.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-1638 (CVE)
°ü·Ã URL 11535 (SecurityFocus)
°ü·Ã URL 17861 (ISS)