English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 13013
À§Çèµµ 30
Æ÷Æ® 88,750
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù Protocol
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â Kerberos 5 ÇÁ·ÎÅäÄÝÀÌ ÀÛµ¿µÇ°í ÀÖ´Ù.
´ÙÀ½°ú °°Àº ¸¹Àº Ãë¾àÁ¡µéÀÌ MIT Kerberos 5 ¸±¸®Áî 1.2.7 ÀÌÇÏ¿¡¼­ ¹ß°ßµÇ¾î ¿Ô´Ù:
- ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ KDC¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.
- ¿ø°ÝÁöÀÇ ¿µ¿ª¿¡ ÀÖ´Â Àΰ¡µÈ »ç¿ëÀÚ°¡ ¾î¶² ¾îÇø®ÄÉÀÌ¼Ç ¼­¹ö¿¡°Ô ´Ù¸¥ ºñ-·ÎÄÃ
»ç¿ëÀÚ·Î Çà»çÇÒ ¼öµµ ÀÖ´Ù.
- ¾î¶² »ç¿ëÀÚ°¡ KDC ½Ã½ºÅÛ°ú µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.
- malloc Ç®(pool)À» ±ú¶ß·Á ÇÁ·Î±×·¥ Å©·¡½¬¸¦ À¯¹ß½Ãų ¼ö ÀÖ´Ù.
- ¾î¶² °íÁ¤µÈ µ¥ÀÌÅÍ¿¡ ´ëÇÑ ºñ±³½Ã¿¡ KDC¿¡ ÀÖ´Â ¹è¿­ÀÇ ³¡À»
Áö³ª°£ µ¥ÀÌÅÍ ÂüÁ¶°¡ ÀϾ ¼ö ÀÖ°í, ÀÌ´Â KDC¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* Note: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Kerberos 5 ¼­ºñ½ºÀÇ Á¸ÀçÀ¯¹« ¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt
http://www.kb.cert.org/vuls/id/587579
http://www.kb.cert.org/vuls/id/787523
http://www.kb.cert.org/vuls/id/661243
http://www.kb.cert.org/vuls/id/684563
http://www.kb.cert.org/vuls/id/623217
http://www.kb.cert.org/vuls/id/442569

* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
Kerberos 5 (krb5) 1.3-alpha1 ÀÌÇÏ
ÇØ°áÃ¥ ´ÙÀ½ MIT Kerberos À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© MIT Kerberos 5ÀÇ °¡Àå ÃֽйöÀü (1.3 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://web.mit.edu/kerberos/www/

-- ȤÀº --

¸¸¾à MIT Kerberos 5ÀÇ ¹öÀü 1.3ÀÌ ¾ÆÁ÷ ³ª¿Í ÀÖÁö ¾Ê´Ù¸é MIT Kerberos À¥ »çÀÌÆ® ( http://web.mit.edu/kerberos/www/ )¸¦ Âü°íÇÏ¿© MIT Kerberos 5ÀÇ ¹öÀü 1.2.7·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ±×¸®°í ´ÙÀ½ MIT Kerberos º¸¾È ±Ç°í¾ÈÀ» Âü°íÇÏ¿© Kerberos 5ÀÇ ÀÏÀÚº° ÆÐÄ¡µéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://web.mit.edu/kerberos/www/advisories/index.html
°ü·Ã URL CVE-2003-0139,CVE-2003-0138,CVE-2003-0072,CVE-2003-0082,CVE-2003-0059,CVE-2003-0060,CVE-2002-0036 (CVE)
°ü·Ã URL 7184,7185,7113,6714,6713,6712 (SecurityFocus)
°ü·Ã URL (ISS)