English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18072
À§Çèµµ 40
Æ÷Æ® 143
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù IMAP
»ó¼¼¼³¸í Mercury IMAP ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
Mercury MailÀº Microsoft Windows ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ MTA(Mail Transfer Agent)·Î SMTP, IMAP, ±×¸®°í POP ¼­¹ö·Î ÀÛµ¿ÇÑ´Ù. Mercury Mail 4.01a¿Í ±× ÀÌÀü ¹öÀüµéÀº IMAP ¼­¹öÀÇ ±¸Çö¿¡ ÀÖ´Â ºÎÀûÀýÇÑ ¹öÆÛ ±æÀÌ °Ë»ç·Î ÀÎÇÑ ´Ù¾çÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. EXAMINE, SUBSCRIBE, STATUS, APPEND µî°ú °°Àº ¿µÇâÀ» ¹Þ´Â IMAP ¸í·É¾îµé ÁßÀÇ Çϳª¿¡ ´ëÇÑ Àμö·Î ¾ÇÀÇÀûÀÎ µ¥ÀÌÅ͸¦ º¸³¿À¸·Î½á, ÀÎÁõ¹ÞÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ¿µÇâÀ» ¹Þ´Â ¼­¹ö ÇÁ·Î¼¼½ºÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ±â°è¾î Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç IMAP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/382929
http://www.securityfocus.com/archive/1/383136

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
David Harris, Pegasus Mercury Mail 4.01a¿Í ±× ÀÌÀü ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ Pegasus Mail ¹èÆ÷ »çÀÌÆ®¿¡¼­ Mercury Mail ¼­¹öÀÇ »õ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://www.pmail.com/downloads_maine_t.htm
°ü·Ã URL CVE-2004-1211 (CVE)
°ü·Ã URL 11775 (SecurityFocus)
°ü·Ã URL 18318 (ISS)