Ãë¾àÁ¡ID |
18055 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
Sendmail 8.6.9´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ IDENT¸¦ ÀÌ¿ëÇÑ root ¸í·ÉµéÀÇ ½ÇÇàÀ» Çã¿ëÇÑ´Ù. SendmailÀº ¸¹Àº Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼ »ç¿ëµÇ´Â Mail Transport Agent (MTA)ÀÌ´Ù. Sendmail 8.6.9ÀÇ IDENT ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡Àº °ø°ÝÀÚµéÀÌ ¿ø°ÝÀ¸·Î root ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Sendmail ¹öÀü 8.6.9´Â »ç¿ëÀÚ Á¤º¸¸¦ ·Î±×Çϱâ À§ÇØ IDENT ¼ºñ½º¿¡ ¿ªÀ¸·Î Á¢¼ÓÀ» ¸Î´Â´Ù. ÀÌ ¹öÀüÀÇ SendmailÀº Ŭ¶óÀÌ¾ðÆ®¿¡ ÀÇÇØ ¹ÝȯµÈ Á¤º¸¸¦ °ËÁõÇÏÁö ¾Ê´Â´Ù. ¸¸¾à Sendmail·Î °Ç³×Áø Ŭ¶óÀÌ¾ðÆ®¿¡ ÀÇÇÑ ÀÀ´äÀÌ ¿¹»ó Ä¡º¸´Ù ´õ ±æ´Ù¸é ÀÀ´äÀº ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŲ´Ù. ÀÌ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ root ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ»ó¿¡ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¾Ë¸² : ´ÙÀ½°ú °°Àº ÀÌÀ¯·Î ÀÎÇÏ¿©, ÀÌ Ãë¾àÁ¡Àº »ç¿ëÀÚÀÇ È¯°æ¿¡¼ º¸¾È À§Çù¿ä¼Ò°¡ µÉ ¼öµµ ÀÖ°í ±×·¸Áö ¾ÊÀ» ¼öµµ ÀÖ´Ù. (Áï, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼öµµ ÀÖ´Ù) 1. ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡ Á¡°ËÀ» À§ÇØ Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ ÀÇÁ¸ÇÑ´Ù. 2. Á¡°Ë¿¡ ÀÌ¿ëµÇ´Â Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸´Â Sendmail ÄÁ¼Ò½Ã¾ö¿¡¼ ¸±¸®ÁîÇÑ Ç¥ÁØ Sendmail ¹èÆ÷ÆÇ¿¡ ±Ù°ÅÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/1995_1/0470.html http://www.cert.org/advisories/CA-95.05.sendmail.vulnerabilities
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sendmail 8.6.9 ConvexOS Any version DG/UX Any version HP Apollo Domain/OS 10.3 HP-UX Any version IRIX Any version Linux Any version NeXTSTEP Any version SCO Unix Any version Solaris Any version UNICOS Any version Ultrix Any version lftpd Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Sendmail À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© SendmailÀÇ °¡Àå ÃֽйöÀü(8.12.10 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: http://www.sendmail.org/8.12.10.html
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡¸¦ ¾Ë¾Æº¸¾Æ¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT ±Ç°í¾ÈÀ» Âü°íÇ϶ó: http://www.cert.org/advisories/CA-95.05.sendmail.vulnerabilities |
°ü·Ã URL |
CVE-1999-0204 (CVE) |
°ü·Ã URL |
2311 (SecurityFocus) |
°ü·Ã URL |
627 (ISS) |
|