Ãë¾àÁ¡ID |
18077 |
À§Çèµµ |
40 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
Exim SMTPÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼¹ö¿¡´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. EximÀº ¹Ì±¹ Ä·ºê¸®Áö ´ëÇп¡¼ ¹èÆ÷ÇÑ °ø°³ ¼Ò½º ±â¹ÝÀÇ MTA(mail transport agent)ÀÌ´Ù. Exim 4.43 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇѵ¥ ÀÌ Ãë¾àÁ¡µéÀº ·ÎÄà °ø°ÝÀÚ°¡ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í »ó½ÂµÈ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:
1) IPv6 ÁÖ¼ÒµéÀ» ó¸®ÇÒ ¶§ "host_aton()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¾Ë·ÁÁ® ÀÖÁö ¾ÊÀº ¸í·ÉÇà ¿É¼Ç¿¡ 8°³ ÀÌ»óÀÇ ±¸¼º¿ä¼Ò¸¦ °¡Áø Àß Á¶ÀÛµÈ IPv6 ÁÖ¼ÒµéÀ» Á¦°øÇÔÀ¸·Î½á ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 2) SPA ÀÎÁõÀ» ó¸®ÇÒ ¶§ "spa_base64_to_bits()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¼º°øÀûÀÎ µµ¿ëÀ» À§Çؼ´Â SPA ÀÎÁõÀ» »ç¿ë ÁßÀ̾î¾ß ÇÑ´Ù. 3) "dns_build_reverse()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¸í·ÉÇà ¿É¼ÇÀ» ÅëÇÏ¿© ¾ÆÁÖ ±ä ¹®ÀÚ¿À» °Ç³ÛÀ¸·Î½á ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Exim SMTP ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.exim.org/mail-archives/exim-announce/2005/msg00000.html http://www.kb.cert.org/vuls/id/132992 http://secunia.com/advisories/13713/ http://www.securitytracker.com/alerts/2005/Jan/1012771.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cambridge University, Exim 4.43 ÀÌÇÏÀÇ ¹öÀüµé Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ SecurityFocus À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://securityfocus.com/bid/12185/solution/
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-635-1À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃֽйöÀü(3.35-1woody4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2005/dsa-635
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¾È GLSA 200501-23À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃֽйöÀü(4.43-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200501-23.xml
For Ubuntu Linux: ´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¾È 2005³â 1¿ù 7ÀÏÀÚ Ubuntu Security Notice USN-56-1À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃÖ½ÅÀÇ exim4 ÆÐŰÁö(4.34-5ubuntu1.1 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://lists.ubuntu.com/archives/ubuntu-security-announce/2005-January/000058.html
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2005-0021,CVE-2005-0022 (CVE) |
°ü·Ã URL |
12185,12188 (SecurityFocus) |
°ü·Ã URL |
18763,18764 (ISS) |
|