English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18049
À§Çèµµ 40
Æ÷Æ® 110
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù POP3
»ó¼¼¼³¸í ÇØ´ç Qpopper POP3 ¼­¹öÀÇ ¹è³Ê¿¡ µû¸£¸é ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Qpopper 4.0.5fc2 ÀÌÀüÀÇ 4.0.x ¹öÀüµé¿¡ ÀÖ´Â pop_msg ÇÔ¼ö´Â Qvsnprintf¸¦ È£ÃâÇÑ ÈÄ¿¡ ¸Þ½ÃÁö ¹öÆÛ¸¦ NULL·Î ³¡³ªµµ·Ï ó¸®ÇØ ÁÖÁö ¾Ê´Â´Ù. º¸¾È Ãë¾àÁ¡Àº mdef' ¸í·ÉÀ» È£ÃâÇϸ鼭 ¾ÇÀÇÀûÀÎ ¸ÅÅ©·Î ¸íÀ» Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù. ÀÌ °áÇÔÀº ÀÎÁõµÈ »ç¿ëÀÚµéÀÌ Qpopper ¼­ºñ½ºÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Qpopper ¼­¹öÀÇ ¹è³Ê¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=bugtraq&m=104739841223916&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=104748775900481&w=2
http://www.debian.org/security/2003/dsa-259
http://marc.theaimsgroup.com/?l=bugtraq&m=104768137314397&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=104792541215354&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Qpopper ¹öÀü 4.0.4 ÀÌÇÏ
ÇØ°áÃ¥ ´ÙÀ½ Qualcomm Qpopper ftp »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© QpopperÀÇ °¡Àå ÃֽйöÀü (4.0.5fc2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.qualcomm.com/eudora/servers/unix/popper/beta/

Debian GNU/Linux 3.0ÀÇ °æ¿ì:
´ÙÀ½ DebianÀÇ º¸¾È ±Ç°í¾È DSA-259-1À» ÂüÁ¶ÇÏ¿© QpopperÀÇ °¡Àå ÃֽйöÀü (4.0.4-9 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-259

±âŸ:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0143 (CVE)
°ü·Ã URL 7058 (SecurityFocus)
°ü·Ã URL (ISS)