Ãë¾àÁ¡ID |
18041 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
ÇØ´ç ¹öÀü 5.0.4 ÀÌÇÏÀÇ Lotus Domino SMTP ¼¹ö´Â ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Lotus SMTP ¼¹ö´Â ÅëÇÕ ¼Ö·ç¼ÇÀÎ Lotus Domino/Notes ¼¹ö ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö¿¡ Æ÷ÇԵǾî Á¦°øµÇ´Â ¸ÞÀÏ ¼¹öÀÌ´Ù. ÀÌ ¼¹ö´Â ¿É¼ÇÀ¸·Î "ENVID" ¶ó´Â Ű¿öµå¸¦ Áö¿øÇÏ´Â µ¥ ´ÙÀ½°ú °°Àº ÇüÅ·Π'MAIL FROM' ¸í·É¾î¿Í ÇÔ²² »ç¿ëµÈ´Ù. (RFC 1891 Âü°í)
MAIL FROM: <test@domain.com> ENVID=<string>
ÀÌ ENVID Ű¿öµå´Â º¸³»´Â ¸Þ½ÃÁö¿¡ ´ëÇØ "envelope identifier" ¸¦ ¸í½ÃÇϱâ À§Çؼ e-mail Ŭ¶óÀÌ¾ðÆ®µé¿¡ ÀÇÇØ »ç¿ëµÇ´Â ¿É¼ÇÀÌ´Ù. ÀÌ ¿É¼ÇÀ» »ç¿ëÇÏ´Â µ¥ ÀÖ¾î¼ SMTP ¼¹ö´Â 'ENVID' Ű¿öµåÀÇ °æ°è(bound)¸¦ ÀûÀýÈ÷ üũÇÏÁö ¾Ê±â ¶§¹®¿¡ "MAIL FROM:" ¸í·É¾î ´ÙÀ½¿¡ Áö³ªÄ¡°Ô ±ä 'ENVID' ½ºÆ®¸µÀ» Æ÷ÇÔÇØ¼ º¸³¾ °æ¿ì, ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ¿© ¼¹ö »ó¿¡¼ ÀÓÀÇÀÇ ¸í·É ½ÇÇàÀÌ °¡´ÉÇÏ´Ù. ÀÌ·¯ÇÑ ¿À¹öÇ÷ο찡 ¼º°øÇÒ °æ¿ì, SMTP ¼¹ö´Â Å©·¡½¬°¡ ¹ß»ýÇÏ¸ç ¸ðµç NotesÀÇ ¼ºñ½º¿¡ ´ëÇØ¼ ´õ ÀÌ»ó Á¤»óÀûÀÎ ±â´ÉÀ» Á¦°øÇÏÁö ¸øÇÏ°Ô µÈ´Ù. ¼¹ö¸¦ Á¤»óÀûÀ¸·Î º¹±¸Çϱâ À§Çؼ´Â Àç½ÃÀÛÇÏ¿©¾ß ÇÏ°í ³ª¾Æ°¡ mail.box ¹× log.nsf ÆÄÀÏÀ» Á¦°ÅÇØ¾ß ÇÒ Çʿ䰡 ÀÖÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/1905 http://www.iss.net/security_center/static/5488.php |
ÇØ°áÃ¥ |
notes.net À¥ »çÀÌÆ®( http://www.notes.net )¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃֽŠLotus Notes/Domino (5.05 ¶Ç´Â ÀÌÈÄ) ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2000-1047 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|