Ãë¾àÁ¡ID |
18053 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
ÇØ´ç Exim SMTP ¼¹öÀÇ ¹öÀüÀº 4.21º¸´Ù ³·´Ù. ¹Ì±¹ Ä·ºê¸®Áö ´ëÇб³¿¡¼ °³¹ßµÈ EximÀº ´Ù¾çÇÑ Unix Ç÷§ÆûµéÀ» À§ÇÑ ¼Ò½º°¡ °ø°³µÈ Mail Transfer Agent ÀÌ´Ù. 4.21 ¹Ì¸¸ÀÇ Exim ¹öÀüµéÀº ±ä HELO ¸í·É¿¡ ÀÇÇÑ Èü(heap) ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¹®Á¦´Â »ç¿ëÀÚ°¡ Á¦°øÇÑ SMTP EHLO/HELO µ¥ÀÌÅ͸¦ Ãë±ÞÇÒ ¶§ ±æÀ̸¦ Á¦´ë·Î °Ë»çÇÏÁö ¸øÇÏ´Â µ¥¿¡ ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼ºñ½º °ÅºÎ °ø°ÝÀ» À¯¹ß½Ãų ¼ö ÀÖ´Ù. ¶ÇÇÑ ºñ·Ï ±¸ÇöÇϱâ Èûµç °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖÁö¸¸ ÀÌ Ãë¾àÁ¡Àº ÀÌ·ÐÀûÀ¸·Î EximÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç SMTP ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-09/0003.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Exim 4.21 ÀÌÀü ¹öÀüµé Conectiva Linux 7.0 ~ 9.0 Debian Linux 3.0 Gentoo Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ 2003³â 8¿ù 14ÀÏ ¸ñ 09:31:54 +0100 (BST)¿¡ Æ÷½ºÆÃµÈ Exim-Announce ¸ÞÀϸµ ¸®½ºÆ®¸¦ ÂüÁ¶ÇÏ¿© EximÀÇ °¡Àå ÃֽйöÀü(4.21 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.exim.org/mirmon/ftp_mirrors.html
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-376-2¿¡ ÀÖ´Â "exim -- buffer overflow"¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Exim ÆÐŰÁö(3.35-3woody1 ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2003/dsa-376
´Ù¸¥ ¹èÆ÷ÆÇ µéÀÇ °æ¿ì: ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0743 (CVE) |
°ü·Ã URL |
8518 (SecurityFocus) |
°ü·Ã URL |
13067 (ISS) |
|