English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22197
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Lotus Domino À¥¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é LDAP ó¸®Äڵ忡 ÀÖ´Â ´ÙÁß Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
LDAP(Lightweight Directory Access Protocol)Àº µð·ºÅ丮 Á¤º¸¸¦ ¾ò°í °ü¸®Çϱâ À§ÇÑ Å¬¶óÀ̾ðÆ®-¼­¹ö ÇÁ·ÎÅäÄÝÀÌ´Ù. Lotus Domino ¼­¹ö »ó¿¡ ±¸ÇöµÈ LDAP¿¡´Â LDAP ¿äû ÆÐŶÀ» ó¸®ÇÏ´Â ÄÚµå »óÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ´Ù¼öÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡µéÀº PROTOS ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ Á¦ÀÛµÈ PROTOS LDAPv3 Å×½ºÆ® ¸ðÀ½À» »ç¿ëÇØ¼­ È®ÀεǾú´Ù. ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇØ¼­, ¿ø°ÝÁö °ø°ÝÀÚµéÀº Domino ¼­¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϰųª ¼­¹ö¸¦ Å©·¡½¬(crash) ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2003-11.html
http://www.kb.cert.org/vuls/id/583184
http://www.rapid7.com/advisories/R7-0012.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Lotus Domino R5 5.0.x
ÇØ°áÃ¥ ¹®Á¦°¡ ÇØ°áµÈ Lotus Domino ¼­¹ö ¹öÀü (R5.0.7a, R6 Gold, 6.0.1) ȤÀº ÃֽйöÀü(6.0.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2001-1311 (CVE)
°ü·Ã URL 7039 (SecurityFocus)
°ü·Ã URL 6895 (ISS)