English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 13012
À§Çèµµ 40
Æ÷Æ® 750
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù Protocol
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â Kerberos 4 ÇÁ·ÎÅäÄÝÀÌ ÀÛµ¿µÇ°í ÀÖ´Ù.
Kerberos 4 ÇÁ·ÎÅäÄÝ¿¡´Â ¸¹Àº ¾Ïȣü°è »óÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾î ¿Ô´Ù. ÀÌ Ãë¾àÁ¡µéÀº µðÀÚÀλóÀÇ °áÇÔÀ¸·Î ÇÁ·ÎÅäÄÝÀÇ ¸ðµç ±¸Çöµé¿¡ ¿µÇâÀ» ¹ÌÄ£´Ù. °¡Àå ½É°¢ÇÑ °ÍÀº °ø°ÝÀÚ°¡ ÇÑ Kerberos ¿µ¿ª ³»¿¡ ÀÖ´Â ¾î¶² ÁÖü(principal)·Î À§ÀåÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̰ÍÀº Kerberos µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯(Domain Controller)¿Í ÀÎÁõÀ» À§ÇØ ±× µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¸¸ ÀÇÁ¸Çϴ ȣ½ºÆ®µéÀ» ¿ÏÀüÈ÷ Àå¾ÇÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. ¶Ç ´Ù¸¥ Ãë¾àÁ¡Àº triple-DES ۵éÀÌ Kerberos 4 ¼­ºñ½ºµé¿¡ ´ëÇÑ Å°·Î »ç¿ëµÈ´Ù¸é Àΰ¡µÇÁö ¾ÊÀº Ŭ¶óÀÌ¾ðÆ® ÁÖü(principal)µé¿¡ ´ëÇØ Kerberos 4 ticketµéÀÇ À§Á¶¸¦ Çã¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt
http://marc.theaimsgroup.com/?l=bugtraq&m=104791775804776&w=2
http://www.debian.org/security/2003/dsa-266
http://www.debian.org/security/2003/dsa-269
http://www.debian.org/security/2003/dsa-273
http://www.redhat.com/support/errata/RHSA-2003-051.html
http://www.redhat.com/support/errata/RHSA-2003-052.html
http://www.redhat.com/support/errata/RHSA-2003-091.html
http://www.kb.cert.org/vuls/id/623217
http://www.kb.cert.org/vuls/id/442569

* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
- Cross-realm(¿µ¿ª±³Â÷) ÀÎÁõÀ» Çã¿ëÇÏ´Â Kerberos ¹öÀü 4 Key Distribution CenterÀÇ ¸ðµç ±¸Çö
- Kerberos ¹öÀü 4 ÇÁ·ÎÅäÄÝÀ» À§ÇÑ KDC¸¦ ±¸ÇöÇÏ°í ¹öÀü 4¿Í ¹öÀü 5¿¡ ´ëÇØ °°Àº ۵éÀ» »ç¿ëÇÏ´Â Kerberos ¹öÀü 5 Key Distribution CenterÀÇ ¸ðµç ±¸Çö
- Kerberos ¹öÀü 4¿¡ ÀÖ´Â triple-DES ۵éÀ» Áö¿øÇÏ´Â Kerberos ¹öÀü 5ÀÇ MIT ±¸Çöµé
ÇØ°áÃ¥ Kerberos 5 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à Kerberos 4¿¡ ¿ªÈ£È¯À» Áö¿øÇÏ´Â Kerberos 5¸¦ °¡µ¿ ÁßÀ̶ó¸é ¹öÀü 1.3À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº MIT krb5 º¸¾È ±Ç°í¾È 2003-004¸¦ º¸¸éµÈ´Ù: http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt

º¥´õ·ÎºÎÅÍ ÆÐÄ¡¸¦ ±¸Çϱâ À§Çؼ­´Â ´ÙÀ½ CERT Ãë¾àÁ¡ ³ëÆ® VU#623217¿¡ ÀÖ´Â "III. Solution"À» º¸¸éµÈ´Ù:
http://www.kb.cert.org/vuls/id/623217
°ü·Ã URL CVE-2003-0138,CVE-2003-0139 (CVE)
°ü·Ã URL 7113 (SecurityFocus)
°ü·Ã URL (ISS)