Ãë¾àÁ¡ID |
18051 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é Àß Á¶ÀÛµÈ ÁÖ¼Ò Çʵ带 ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì(2) °ø°Ý¿¡ Ãë¾àÇÏ´Ù. SendmailÀº ¸¹Àº Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼ »ç¿ëµÇ´Â MTA (mail transfer agent)ÀÌ´Ù. Sendmail 5.2¿¡¼ 8.12.8 »çÀÌÀÇ ¹öÀüµéÀº ¸ÞÀÏ Çì´õ ÇʵåµéÀ» ó¸®ÇÏ´Â Äڵ忡 ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Sendmail 8.12.9 ÀÌÀü ¹öÀü¿¡ ÀÖ´Â prescan ÇÔ¼ö´Â email ÁÖ¼Ò¸¦ ºÐÇØÇÏ¿© Àß Ã³¸®µÉ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ÀÌ ÇÔ¼ö´Â email ÁÖ¼ÒµéÀÇ ±æÀ̸¦ ÀûÀýÇÏ°Ô Ã¼Å©ÇÏÁö ¸øÇÏ´Â °áÇÔÀ» °¡Áö°í ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚ ÀÌ Ã¼Å©µéÀ» ¿ìȸÇÒ ¼ö ÀÖ´Â Àß °í¾ÈµÈ ±ä ¹®ÀÚ¿À» ¸¸µé¾î ½ºÅÿ¡ µ¥ÀÌÅÍ¿Í ÀÓÀÇÀÇ Äڵ带 ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Àß Á¶ÀÛµÈ "From", "To", ȤÀº "CC" Çì´õ Çʵ带 °¡Áø EmailÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ã۰í Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇÑ root ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* ¾Ë¸² : ´ÙÀ½°ú °°Àº ÀÌÀ¯·Î ÀÎÇÏ¿©, ÀÌ Ãë¾àÁ¡Àº »ç¿ëÀÚÀÇ È¯°æ¿¡¼ º¸¾È À§Çù¿ä¼Ò°¡ µÉ ¼öµµ ÀÖ°í ±×·¸Áö ¾ÊÀ» ¼öµµ ÀÖ´Ù. (Áï, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼öµµ ÀÖ´Ù) 1. ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡ Á¡°ËÀ» À§ÇØ Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ ÀÇÁ¸ÇÑ´Ù. 2. Á¡°Ë¿¡ ÀÌ¿ëµÇ´Â Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸´Â Sendmail ÄÁ¼Ò½Ã¾ö¿¡¼ ¸±¸®ÁîÇÑ Ç¥ÁØ Sendmail ¹èÆ÷ÆÇ¿¡ ±Ù°ÅÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=104897487512238&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=104896621106790&w=2 http://www.cert.org/advisories/CA-2003-12.html http://www.kb.cert.org/vuls/id/897604 ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc http://www.redhat.com/support/errata/RHSA-2003-120.html http://www.redhat.com/support/errata/RHSA-2003-121.html http://marc.theaimsgroup.com/?l=bugtraq&m=104914999806315&w=2
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sendmail Pro (all versions) Sendmail Switch 2.1.6 ÀÌÀüÀÇ 2.1 Sendmail Switch 2.2.6 ÀÌÀüÀÇ 2.2 Sendmail Switch 3.0.4 ÀÌÀüÀÇ 3.0 Sendmail for NT 2.6.3 ÀÌÀüÀÇ 2.X Sendmail for NT 3.0.4 ÀÌÀüÀÇ 3.0 Open-source Sendmail 8.12.9 ÀÌÀü ¹öÀüµé IBM AIX OpenBSD Sun Solaris 2.6, 7, 8 ±×¸®°í 9 Red Hat Linux Conectiva Linux SuSE Linux Slackware Gentoo Linux |
ÇØ°áÃ¥ |
´ÙÀ½ Sendmail À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© SendmailÀÇ °¡Àå ÃֽйöÀü (8.12.9 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵åÇϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.sendmail.org/pub/sendmail/
Sun SolarisÀÇ °æ¿ì: ´ÙÀ½ Sun º¸¾È ±Ç°í¾È VU#897604¸¦ Âü°íÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.oracle.com/sunalerts/1000625.1.html
IBM AIXÀÇ °æ¿ì: º¥´õ¿¡ ¹®ÀÇÇϰųª ´ÙÀ½ÀÇ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÆÐÄ¡¸¦ ½Ã½ºÅÛ¿¡ ¼³Ä¡ÇÑ´Ù. http://www-933.ibm.com/support/fixcentral/
APAR number for AIX 4.3.3: IY42629 APAR number for AIX 5.1.0: IY42630 APAR number for AIX 5.2.0: IY42631
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡¸¦ ¾Ë¾Æº¸¾Æ¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT ±Ç°í¾ÈÀ» Âü°íÇÑ´Ù. http://www.cert.org/advisories/CA-2003-12.html |
°ü·Ã URL |
CVE-2003-0161 (CVE) |
°ü·Ã URL |
7230 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|