Ãë¾àÁ¡ID |
19012 |
À§Çèµµ |
30 |
Æ÷Æ® |
53 |
ÇÁ·ÎÅäÄÝ |
TCP,UDP |
ºÐ·ù |
DNS |
»ó¼¼¼³¸í |
ÇØ´ç BIND ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ¼¹ö´Â °ø°ÝÀÚ°¡ ¼ºñ½º¸¦ ¿ø°ÝÀ¸·Î ÀÛµ¿ ÁßÁö½Ãų ¼ö ÀÖ´Â Negative Cache Poison ¹ö±×¿¡ Ãë¾àÇÏ´Ù. ISC BIND 8.3.7 ÀÌÀüÀÇ 8.3.x, ±×¸®°í 8.4.3 ÀÌÀüÀÇ 8.4.x ¹öÀüµéÀº Negative ÀÀ´äµéÀ» ÅëÇÑ Cache Poisoning(ij½¬ Á¤º¸ ÆÄ±«)¿¡ Ãë¾àÇÏ´Ù. °ø°ÝÀÚ´Â ¸ñÇ¥ ³×ÀÓ ¼¹ö·Î ¹è´ÞµÇµµ·Ï ¾ÇÀÇÀûÀÎ DNS ¸Þ½ÃÁöµéÀ» ¸¸µé°í, ¸ñÇ¥ ³×ÀÓ ¼¹ö°¡ ¸î¸î ¸ñÇ¥ µµ¸ÞÀÎ ¸í¿¡ ´ëÇÑ Negative ÀÀ´äÀ» ij½¬Çϵµ·Ï Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î ¸ñÇ¥ ³×ÀÓ ¼¹ö´Â ¸ñÇ¥ µµ¸ÞÀÎ ¸í¿¡ ´ëÇÑ ÇÕ¹ýÀûÀÎ ÁúÀǵ鿡 Negative ÇÏ°Ô ÀÀ´äÇÏ¿© DNS¸¦ ÇÊ¿ä·Î ÇÏ´Â ¾îÇø®ÄÉÀ̼ǵ鿡 ´ëÇÑ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å²´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç BIND ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/734644 http://www.isc.org/products/BIND/bind8.html http://marc.theaimsgroup.com/?l=bind-announce&m=106988846219834&w=2 http://marc.theaimsgroup.com/?l=bind-announce&m=106988846919846&w=2 http://secunia.com/advisories/10300/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ISC BIND 8.3.7 ÀÌÀüÀÇ 8.3.x, ±×¸®°í 8.4.3 ÀÌÀüÀÇ 8.4.x HP-UX B.11.00 ±×¸®°í B.11.11 Solaris 7, 8 ±×¸®°í 9 FreeBSD IBM AIX Linux Any version UNIX Any version |
ÇØ°áÃ¥ |
Á¦Á¶ ¾÷ü·ÎºÎÅÍ ÆÐÄ¡³ª ¾÷±×·¹À̵åµÈ ¹öÀüÀ» ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. ISC´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ BIND 8.3.7°ú BIND 8.4.3¸¦ ³» ³õ¾Ò´Ù. BIND 4°¡ ±¸µ¿ ÁßÀÎ ³×ÀÓ ¼¹öµéÀº ¹®Á¦°¡ ¾ø´Ù. BINDÀÇ °¡Àå ÃֽйöÀüµéÀº http://www.isc.org/products/BIND/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Ù.
´ÙÀ½ Hewlett-Packard»ç º¸¾È °Ô½Ã¹° HPSBUX0311-303À» Âü°íÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.kb.cert.org/vuls/id/JPLA-5SJT2P
Sun Solaris 7, 8 ±×¸®°í 9ÀÇ °æ¿ì: ´ÙÀ½ SunSolve À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.oracle.com/sunalerts/1000259.1.html
IBM AIXÀÇ °æ¿ì: ´ÙÀ½¿¡ ÀÖ´Â IBM AIX APAR ¹®¼¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.kb.cert.org/vuls/id/JPLA-5SJT2Y
FreeBSDÀÇ °æ¿ì: ´ÙÀ½ FreeBSD »çÀÇ º¸¾È °Ô½Ã¹° FreeBSD-SA-03:19.bind¸¦ ÂüÁ¶ÇÏ¿© 2003-11-28¿¡ ³ª¿Â ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:19.bind.asc
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT Vulnerability Note VU#734644À» ÂüÁ¶ÇÑ´Ù: http://www.kb.cert.org/vuls/id/734644 |
°ü·Ã URL |
CVE-2003-0914 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|