English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18053
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç Exim SMTP ¼­¹öÀÇ ¹öÀüÀº 4.21º¸´Ù ³·´Ù.
¹Ì±¹ Ä·ºê¸®Áö ´ëÇб³¿¡¼­ °³¹ßµÈ EximÀº ´Ù¾çÇÑ Unix Ç÷§ÆûµéÀ» À§ÇÑ ¼Ò½º°¡ °ø°³µÈ Mail Transfer Agent ÀÌ´Ù. 4.21 ¹Ì¸¸ÀÇ Exim ¹öÀüµéÀº ±ä HELO ¸í·É¿¡ ÀÇÇÑ Èü(heap) ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¹®Á¦´Â »ç¿ëÀÚ°¡ Á¦°øÇÑ SMTP EHLO/HELO µ¥ÀÌÅ͸¦ Ãë±ÞÇÒ ¶§ ±æÀ̸¦ Á¦´ë·Î °Ë»çÇÏÁö ¸øÇÏ´Â µ¥¿¡ ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼­ºñ½º °ÅºÎ °ø°ÝÀ» À¯¹ß½Ãų ¼ö ÀÖ´Ù. ¶ÇÇÑ ºñ·Ï ±¸ÇöÇϱâ Èûµç °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖÁö¸¸ ÀÌ Ãë¾àÁ¡Àº ÀÌ·ÐÀûÀ¸·Î EximÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç SMTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-09/0003.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Exim 4.21 ÀÌÀü ¹öÀüµé
Conectiva Linux 7.0 ~ 9.0
Debian Linux 3.0
Gentoo Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ 2003³â 8¿ù 14ÀÏ ¸ñ 09:31:54 +0100 (BST)¿¡ Æ÷½ºÆÃµÈ Exim-Announce ¸ÞÀϸµ ¸®½ºÆ®¸¦ ÂüÁ¶ÇÏ¿© EximÀÇ °¡Àå ÃֽйöÀü(4.21 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.exim.org/mirmon/ftp_mirrors.html

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-376-2¿¡ ÀÖ´Â "exim -- buffer overflow"¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Exim ÆÐŰÁö(3.35-3woody1 ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-376

´Ù¸¥ ¹èÆ÷ÆÇ µéÀÇ °æ¿ì:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0743 (CVE)
°ü·Ã URL 8518 (SecurityFocus)
°ü·Ã URL 13067 (ISS)