Ãë¾àÁ¡ID |
13013 |
À§Çèµµ |
30 |
Æ÷Æ® |
88,750 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
Protocol |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â Kerberos 5 ÇÁ·ÎÅäÄÝÀÌ ÀÛµ¿µÇ°í ÀÖ´Ù. ´ÙÀ½°ú °°Àº ¸¹Àº Ãë¾àÁ¡µéÀÌ MIT Kerberos 5 ¸±¸®Áî 1.2.7 ÀÌÇÏ¿¡¼ ¹ß°ßµÇ¾î ¿Ô´Ù: - ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ KDC¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù. - ¿ø°ÝÁöÀÇ ¿µ¿ª¿¡ ÀÖ´Â Àΰ¡µÈ »ç¿ëÀÚ°¡ ¾î¶² ¾îÇø®ÄÉÀÌ¼Ç ¼¹ö¿¡°Ô ´Ù¸¥ ºñ-·ÎÄà »ç¿ëÀÚ·Î Çà»çÇÒ ¼öµµ ÀÖ´Ù. - ¾î¶² »ç¿ëÀÚ°¡ KDC ½Ã½ºÅÛ°ú µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù. - malloc Ç®(pool)À» ±ú¶ß·Á ÇÁ·Î±×·¥ Å©·¡½¬¸¦ À¯¹ß½Ãų ¼ö ÀÖ´Ù. - ¾î¶² °íÁ¤µÈ µ¥ÀÌÅÍ¿¡ ´ëÇÑ ºñ±³½Ã¿¡ KDC¿¡ ÀÖ´Â ¹è¿ÀÇ ³¡À» Áö³ª°£ µ¥ÀÌÅÍ ÂüÁ¶°¡ ÀϾ ¼ö ÀÖ°í, ÀÌ´Â KDC¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.
* Note: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Kerberos 5 ¼ºñ½ºÀÇ Á¸ÀçÀ¯¹« ¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt http://www.kb.cert.org/vuls/id/587579 http://www.kb.cert.org/vuls/id/787523 http://www.kb.cert.org/vuls/id/661243 http://www.kb.cert.org/vuls/id/684563 http://www.kb.cert.org/vuls/id/623217 http://www.kb.cert.org/vuls/id/442569
* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î: Kerberos 5 (krb5) 1.3-alpha1 ÀÌÇÏ |
ÇØ°áÃ¥ |
´ÙÀ½ MIT Kerberos À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© MIT Kerberos 5ÀÇ °¡Àå ÃֽйöÀü (1.3 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://web.mit.edu/kerberos/www/
-- ȤÀº --
¸¸¾à MIT Kerberos 5ÀÇ ¹öÀü 1.3ÀÌ ¾ÆÁ÷ ³ª¿Í ÀÖÁö ¾Ê´Ù¸é MIT Kerberos À¥ »çÀÌÆ® ( http://web.mit.edu/kerberos/www/ )¸¦ Âü°íÇÏ¿© MIT Kerberos 5ÀÇ ¹öÀü 1.2.7·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ±×¸®°í ´ÙÀ½ MIT Kerberos º¸¾È ±Ç°í¾ÈÀ» Âü°íÇÏ¿© Kerberos 5ÀÇ ÀÏÀÚº° ÆÐÄ¡µéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://web.mit.edu/kerberos/www/advisories/index.html |
°ü·Ã URL |
CVE-2003-0139,CVE-2003-0138,CVE-2003-0072,CVE-2003-0082,CVE-2003-0059,CVE-2003-0060,CVE-2002-0036 (CVE) |
°ü·Ã URL |
7184,7185,7113,6714,6713,6712 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|