Ãë¾àÁ¡ID |
14034 |
À§Çèµµ |
40 |
Æ÷Æ® |
22 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Ssh |
»ó¼¼¼³¸í |
ÇØ´ç LSH µ¥¸óÀÇ ¹öÀü¿¡ ÀÇÇϸé Èü(Heap) ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. LSH´Â Unix¿Í Linux °è¿ÀÇ ¿î¿µÃ¼Á¦¸¦ À§ÇØ ¹«·á·Î »ç¿ë °¡´ÉÇÑ SSH ¹öÀü 2 ÇÁ·ÎÅäÄÝÀÇ ±¸ÇöÀÌ´Ù. ÀÌ LSH µ¥¸óÀÇ 1.5.3 ÀÌÀü ¹öÀüµé¿¡´Â ºÎÀûÀýÇÑ °æ°è °Ë»ç·Î ÀÎÇÑ Èü(Heap) ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇϸé root ±ÇÇÑÀ¸·Î ½Ã½ºÅÛÀÇ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ LSH µ¥¸óÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-09/0310.html http://archives.neohapsis.com/archives/bugtraq/2003-09/0326.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: LSH 1.5, 1.5.1, 1.5.2 LSH 1.4.3 ÀÌÀü ¹öÀüµé Linux ½Ã½ºÅÛ Unix ½Ã½ºÅÛ |
ÇØ°áÃ¥ |
´ÙÀ½ÀÇ LSH À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© LSH 1.4.3 ÀÌ»ó(LSH 1.4.3 ÀÌÀü ¹öÀüµéÀÇ °æ¿ì) ¶Ç´Â LSH 1.5.3 ÀÌ»ó(LSH 1.5.3 ÀÌÀü ¹öÀüµéÀÇ °æ¿ì)À¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù: http://www.lysator.liu.se/~nisse/lsh |
°ü·Ã URL |
CVE-2003-0826 (CVE) |
°ü·Ã URL |
8655 (SecurityFocus) |
°ü·Ã URL |
13245 (ISS) |
|