English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18077
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í Exim SMTPÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. EximÀº ¹Ì±¹ Ä·ºê¸®Áö ´ëÇп¡¼­ ¹èÆ÷ÇÑ °ø°³ ¼Ò½º ±â¹ÝÀÇ MTA(mail transport agent)ÀÌ´Ù. Exim 4.43 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇѵ¥ ÀÌ Ãë¾àÁ¡µéÀº ·ÎÄà °ø°ÝÀÚ°¡ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í »ó½ÂµÈ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:

1) IPv6 ÁÖ¼ÒµéÀ» ó¸®ÇÒ ¶§ "host_aton()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¾Ë·ÁÁ® ÀÖÁö ¾ÊÀº ¸í·ÉÇà ¿É¼Ç¿¡ 8°³ ÀÌ»óÀÇ ±¸¼º¿ä¼Ò¸¦ °¡Áø Àß Á¶ÀÛµÈ IPv6 ÁÖ¼ÒµéÀ» Á¦°øÇÔÀ¸·Î½á ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) SPA ÀÎÁõÀ» ó¸®ÇÒ ¶§ "spa_base64_to_bits()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¼º°øÀûÀÎ µµ¿ëÀ» À§Çؼ­´Â SPA ÀÎÁõÀ» »ç¿ë ÁßÀ̾î¾ß ÇÑ´Ù.
3) "dns_build_reverse()" ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ±æÀÌ(boundary) ¿¡·¯´Â ¸í·ÉÇà ¿É¼ÇÀ» ÅëÇÏ¿© ¾ÆÁÖ ±ä ¹®ÀÚ¿­À» °Ç³ÛÀ¸·Î½á ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½ÃŰ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Exim SMTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.exim.org/mail-archives/exim-announce/2005/msg00000.html
http://www.kb.cert.org/vuls/id/132992
http://secunia.com/advisories/13713/
http://www.securitytracker.com/alerts/2005/Jan/1012771.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cambridge University, Exim 4.43 ÀÌÇÏÀÇ ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ SecurityFocus À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://securityfocus.com/bid/12185/solution/

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-635-1À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃֽйöÀü(3.35-1woody4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2005/dsa-635

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¾È GLSA 200501-23À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃֽйöÀü(4.43-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200501-23.xml

For Ubuntu Linux:
´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¾È 2005³â 1¿ù 7ÀÏÀÚ Ubuntu Security Notice USN-56-1À» ÂüÁ¶ÇÏ¿© eximÀÇ °¡Àå ÃÖ½ÅÀÇ exim4 ÆÐŰÁö(4.34-5ubuntu1.1 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://lists.ubuntu.com/archives/ubuntu-security-announce/2005-January/000058.html

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2005-0021,CVE-2005-0022 (CVE)
°ü·Ã URL 12185,12188 (SecurityFocus)
°ü·Ã URL 18763,18764 (ISS)