Ãë¾àÁ¡ID |
18046 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é Àß Á¶ÀÛµÈ ÁÖ¼Ò Çʵ带 ÅëÇÑ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù. SendmailÀº ¸¹Àº Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼ »ç¿ëµÇ´Â MTA (mail transfer agent)ÀÌ´Ù. Sendmail 5.2¿¡¼ 8.12.7 »çÀÌÀÇ ¹öÀüµéÀº ¸ÞÀÏ Çì´õ ÇʵåµéÀ» ó¸®ÇÏ´Â Äڵ忡 ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. SendmailÀº ¹®ÀÚµéÀÌ ¿Ã¹Ù¸£°Ô ÇØ¼®µÇ°í ÀÖ´ÂÁö¸¦ È®½ÇÈ÷ ÇØ µÎ±â À§ÇÑ ¸î°¡Áö º¸¾È üũµéÀ» ±¸ÇöÇØ ³õ°í ÀÖ´Ù. ƯÈ÷, ("From" Çʵå, "To" ÇÊµå ±×¸®°í "CC" Çʵå¿Í °°Àº) ÁÖ¼Ò³ª ÁÖ¼ÒµéÀÇ ¸®½ºÆ®¸¦ Æ÷ÇÔÇϰí ÀÖ´Â Çʵ尡 ÀÖÀ» ¶§, SendmailÀº Á¦°øµÈ ÁÖ¼Ò (ȤÀº ÁÖ¼ÒµéÀÇ ¸®½ºÆ®)°¡ Ÿ´çÇÑÁö¸¦ Àǹ̷РÀûÀ¸·Î Æò°¡ÇÏ·Á°í ÇÑ´Ù. ÀÌ Áß ÇϳªÀÇ º¸¾È üũ¿¡ °áÇÔÀÌ ÀÖÀ¸¸ç, ÀÌ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Àß Á¶ÀÛµÈ ÁÖ¼Ò Çʵ带 °¡Áø EmailÀ» º¸³» ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Àß Á¶ÀÛµÈ "From", "To", ȤÀº "CC" Çì´õ Çʵ带 °¡Áø EmailÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â "skipping" ¸ðµåÀÇ Email Çì´õ üũ¸¦ ¿ìȸÇÒ ¼ö ÀÖÀ¸¸ç Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇÑ root ±ÇÇÑÀ» ¾ò¾î³»±â À§ÇØ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ´ÙÀ½ ÀÌÀ¯µé ¶§¹®¿¡ »ç¿ëÀÚÀÇ È¯°æ¿¡¼´Â º¸¾È À§Çù¿ä¼ÒÀÏ ¼öµµ, ¾Æ´Ò ¼öµµ ÀÖ´Ù (Áï, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)ÀÏ ¼ö ÀÖ´Ù): 1. ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. 2. Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸´Â Sendmail ÄÁ¼Ò½Ã¾ö¿¡¼ ¸±¸®ÁîÇÑ Ç¥ÁØ Sendmail ¹èÆ÷ÆÇ¿¡ ±Ù°ÅÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-2003-07.html http://www.sendmail.org/8.12.8.html http://www.kb.cert.org/vuls/id/398025 http://www.iss.net/security_center/static/7622.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Unix ¸ðµç ¹öÀü HP HP-UX 10.10,10.20,11.04,11.0,11.11,11.22 Solaris 2.6, 7, 8 ±×¸®°í 9 FreeBSD < 4.8-RELEASE FreeBSD < 5.0-RELEASE-p4 FreeBSD-stable 2003-03-03 ÀÌÀü ¹öÀü IRIX 6.5.19 ÀÌÇÏ ¹öÀü Linux ¸ðµç ¹öÀü Mandrake Linux 7.2, 8.0, 8.1, 8.2, 9.0 Mandrake Linux Corporate Server 1.0.1 Red Hat Linux 6.2, 7.x, Linux 8.0 |
ÇØ°áÃ¥ |
´ÙÀ½ Sendmail À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© SendmailÀÇ °¡Àå ÃֽйöÀü (8.12.8 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵åÇϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: http://www.sendmail.org/8.12.8.html
Sun SolarisÀÇ °æ¿ì: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾Æ·¡ÀÇ ÆÐÄ¡¸¦ ½Ã½ºÅÛ¿¡ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à Oracle»ç¿¡¼ Áö¿øÇÏ´Â Solaris ¹öÀüÀÌ¸é ´ÙÀ½ »çÀÌÆ®¿¡¼ ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Ù. http://support.oracle.com
SPARC: Solaris 2.6: 105395-08 or later Solaris 7: 107684-08 or later Solaris 8: 110615-08 or later Solaris 9: 113575-03 or later
x86: Solaris 2.6: 105396-08 or later Solaris 7: 107685-08 or later Solaris 8: 110616-08 or later Solaris 9: 114137-02 or late
SGI IRIXÀÇ °æ¿ì: ´ÙÀ½ SGI º¸¾È ±Ç°í¾È 20030301-01-PÀ» Âü°íÇÏ¿© IRIXÀÇ °¡Àå ÃֽйöÀü (6.5.20 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵åÇϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: ftp://patches.sgi.com/support/free/security/advisories/20030301-01-P
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2003:073-06À» Âü°íÇÏ¿© ¾Æ·¡¿¡ ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.redhat.com/support/errata/RHSA-2003-073.html
Red Hat 6.2: 8.11.6-1.62.2 ȤÀº ÀÌÈÄ Red Hat 7.0: 8.11.6-23.70 ȤÀº ÀÌÈÄ Red Hat 7.1: 8.11.6-23.71 ȤÀº ÀÌÈÄ Red Hat 7.2: 8.11.6-23.72 ȤÀº ÀÌÈÄ Red Hat 7.3: 8.11.6-23.73 ȤÀº ÀÌÈÄ Red Hat 8.0: 8.12.8-1.80 ȤÀº ÀÌÈÄ
FreeBSDÀÇ °æ¿ì: ´ÙÀ½ FreeBSD º¸¾È ±Ç°í¾È FreeBSD-SA-03:04.sendmail .smrsh¸¦ Âü°íÇÏ¿© FreeBSDÀÇ °¡Àå ÃֽйöÀü (4-STABLE ÀÌ»ó), ȤÀº 2003-03-03 security branch ÀÌÈÄÀÇ ³¯Â¥·Î µÈ RELENG_5_0, RELENG_4_7, or RELENG_4_6À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:04.sendmail.asc
Mandrake-LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft º¸¾È ±Ç°í¾È MDKSA-2003:028À» Âü°íÇÏ¿© ¾Æ·¡¿¡ ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ sendmail ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
Linux-Mandrake 7.2: 8.11.0-4.2mdk ȤÀº ÀÌÈÄ Mandrake Linux 8.0 and 8.1: 8.11.6-4.4mdk ȤÀº ÀÌÈÄ Mandrake Linux 8.2: 8.12.1-4.2mdk ȤÀº ÀÌÈÄ Mandrake Linux 9.0 and Corporate Server 2.1: 8.12.6-3.2mdk ȤÀº ÀÌÈÄ
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡¸¦ ¾Ë¾Æº¸¾Æ¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-1337 (CVE) |
°ü·Ã URL |
6991 (SecurityFocus) |
°ü·Ã URL |
10748 (ISS) |
|