Ãë¾àÁ¡ID |
13012 |
À§Çèµµ |
40 |
Æ÷Æ® |
750 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
Protocol |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â Kerberos 4 ÇÁ·ÎÅäÄÝÀÌ ÀÛµ¿µÇ°í ÀÖ´Ù. Kerberos 4 ÇÁ·ÎÅäÄÝ¿¡´Â ¸¹Àº ¾Ïȣü°è »óÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾î ¿Ô´Ù. ÀÌ Ãë¾àÁ¡µéÀº µðÀÚÀλóÀÇ °áÇÔÀ¸·Î ÇÁ·ÎÅäÄÝÀÇ ¸ðµç ±¸Çöµé¿¡ ¿µÇâÀ» ¹ÌÄ£´Ù. °¡Àå ½É°¢ÇÑ °ÍÀº °ø°ÝÀÚ°¡ ÇÑ Kerberos ¿µ¿ª ³»¿¡ ÀÖ´Â ¾î¶² ÁÖü(principal)·Î À§ÀåÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̰ÍÀº Kerberos µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯(Domain Controller)¿Í ÀÎÁõÀ» À§ÇØ ±× µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¸¸ ÀÇÁ¸Çϴ ȣ½ºÆ®µéÀ» ¿ÏÀüÈ÷ Àå¾ÇÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. ¶Ç ´Ù¸¥ Ãë¾àÁ¡Àº triple-DES ۵éÀÌ Kerberos 4 ¼ºñ½ºµé¿¡ ´ëÇÑ Å°·Î »ç¿ëµÈ´Ù¸é Àΰ¡µÇÁö ¾ÊÀº Ŭ¶óÀÌ¾ðÆ® ÁÖü(principal)µé¿¡ ´ëÇØ Kerberos 4 ticketµéÀÇ À§Á¶¸¦ Çã¿ëÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt http://marc.theaimsgroup.com/?l=bugtraq&m=104791775804776&w=2 http://www.debian.org/security/2003/dsa-266 http://www.debian.org/security/2003/dsa-269 http://www.debian.org/security/2003/dsa-273 http://www.redhat.com/support/errata/RHSA-2003-051.html http://www.redhat.com/support/errata/RHSA-2003-052.html http://www.redhat.com/support/errata/RHSA-2003-091.html http://www.kb.cert.org/vuls/id/623217 http://www.kb.cert.org/vuls/id/442569
* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î: - Cross-realm(¿µ¿ª±³Â÷) ÀÎÁõÀ» Çã¿ëÇÏ´Â Kerberos ¹öÀü 4 Key Distribution CenterÀÇ ¸ðµç ±¸Çö - Kerberos ¹öÀü 4 ÇÁ·ÎÅäÄÝÀ» À§ÇÑ KDC¸¦ ±¸ÇöÇÏ°í ¹öÀü 4¿Í ¹öÀü 5¿¡ ´ëÇØ °°Àº ۵éÀ» »ç¿ëÇÏ´Â Kerberos ¹öÀü 5 Key Distribution CenterÀÇ ¸ðµç ±¸Çö - Kerberos ¹öÀü 4¿¡ ÀÖ´Â triple-DES ۵éÀ» Áö¿øÇÏ´Â Kerberos ¹öÀü 5ÀÇ MIT ±¸Çöµé |
ÇØ°áÃ¥ |
Kerberos 5 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à Kerberos 4¿¡ ¿ªÈ£È¯À» Áö¿øÇÏ´Â Kerberos 5¸¦ °¡µ¿ ÁßÀ̶ó¸é ¹öÀü 1.3À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº MIT krb5 º¸¾È ±Ç°í¾È 2003-004¸¦ º¸¸éµÈ´Ù: http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt
º¥´õ·ÎºÎÅÍ ÆÐÄ¡¸¦ ±¸Çϱâ À§Çؼ´Â ´ÙÀ½ CERT Ãë¾àÁ¡ ³ëÆ® VU#623217¿¡ ÀÖ´Â "III. Solution"À» º¸¸éµÈ´Ù: http://www.kb.cert.org/vuls/id/623217 |
°ü·Ã URL |
CVE-2003-0138,CVE-2003-0139 (CVE) |
°ü·Ã URL |
7113 (SecurityFocus) |
°ü·Ã URL |
(ISS) |