English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18055
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í Sendmail 8.6.9´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ IDENT¸¦ ÀÌ¿ëÇÑ root ¸í·ÉµéÀÇ ½ÇÇàÀ» Çã¿ëÇÑ´Ù.
SendmailÀº ¸¹Àº Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼­ »ç¿ëµÇ´Â Mail Transport Agent (MTA)ÀÌ´Ù. Sendmail 8.6.9ÀÇ IDENT ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡Àº °ø°ÝÀÚµéÀÌ ¿ø°ÝÀ¸·Î root ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Sendmail ¹öÀü 8.6.9´Â »ç¿ëÀÚ Á¤º¸¸¦ ·Î±×Çϱâ À§ÇØ IDENT ¼­ºñ½º¿¡ ¿ªÀ¸·Î Á¢¼ÓÀ» ¸Î´Â´Ù. ÀÌ ¹öÀüÀÇ SendmailÀº Ŭ¶óÀÌ¾ðÆ®¿¡ ÀÇÇØ ¹ÝȯµÈ Á¤º¸¸¦ °ËÁõÇÏÁö ¾Ê´Â´Ù. ¸¸¾à Sendmail·Î °Ç³×Áø Ŭ¶óÀÌ¾ðÆ®¿¡ ÀÇÇÑ ÀÀ´äÀÌ ¿¹»ó Ä¡º¸´Ù ´õ ±æ´Ù¸é ÀÀ´äÀº ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŲ´Ù. ÀÌ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ root ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ»ó¿¡ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* ¾Ë¸² : ´ÙÀ½°ú °°Àº ÀÌÀ¯·Î ÀÎÇÏ¿©, ÀÌ Ãë¾àÁ¡Àº »ç¿ëÀÚÀÇ È¯°æ¿¡¼­ º¸¾È À§Çù¿ä¼Ò°¡ µÉ ¼öµµ ÀÖ°í ±×·¸Áö ¾ÊÀ» ¼öµµ ÀÖ´Ù. (Áï, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼öµµ ÀÖ´Ù)
1. ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡ Á¡°ËÀ» À§ÇØ Sendmail ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ ÀÇÁ¸ÇÑ´Ù.
2. Á¡°Ë¿¡ ÀÌ¿ëµÇ´Â Sendmail ¼­¹öÀÇ ¹öÀü Á¤º¸´Â Sendmail ÄÁ¼Ò½Ã¾ö¿¡¼­ ¸±¸®ÁîÇÑ Ç¥ÁØ Sendmail ¹èÆ÷ÆÇ¿¡ ±Ù°ÅÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/1995_1/0470.html
http://www.cert.org/advisories/CA-95.05.sendmail.vulnerabilities

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Sendmail 8.6.9
ConvexOS Any version
DG/UX Any version
HP Apollo Domain/OS 10.3
HP-UX Any version
IRIX Any version
Linux Any version
NeXTSTEP Any version
SCO Unix Any version
Solaris Any version
UNICOS Any version
Ultrix Any version
lftpd Any version
ÇØ°áÃ¥ ´ÙÀ½ Sendmail À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© SendmailÀÇ °¡Àå ÃֽйöÀü(8.12.10 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://www.sendmail.org/8.12.10.html

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡¸¦ ¾Ë¾Æº¸¾Æ¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT ±Ç°í¾ÈÀ» Âü°íÇ϶ó:
http://www.cert.org/advisories/CA-95.05.sendmail.vulnerabilities
°ü·Ã URL CVE-1999-0204 (CVE)
°ü·Ã URL 2311 (SecurityFocus)
°ü·Ã URL 627 (ISS)