English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22198
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Lotus Domino ¼­¹öÀÇ Web Retriever ÇÁ·Î±×·¥Àº ±ä HTTP »óÅ ¸Þ½ÃÁö·Î ÀÎÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼­ºñ½º °ÅºÎ(Denial of Service) °ø°ÝÀ» À§ÇØ µµ¿ëµÉ ¼ö ÀÖ´Ù. Lotus Notes/Domino Web Retriever´Â Notes »ç¿ëÀڵ鿡°Ô À¥ ÆäÀÌÁö¸¦ ¹ÝÈ¯ÇØ ÁÖ´Â ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ Web Retriever´Â ¿ø°Ý À¥ ¼­¹ö·ÎºÎÅÍ Áö³ªÄ¡°Ô ±ä HTTP »óÅ ¸Þ½ÃÁö¸¦ Àü´Þ¹ÞÀ» °æ¿ì, Å©·¡½¬(crash) µÈ´Ù. ¸¸¾à, Web Retriever°¡ ¼­¹ö¿¡¼­ µ¿ÀÛÇÑ´Ù¸é, ¼­¹ö »ó¿¡ ¼­ºñ½º °ÅºÎ(Denial of Service)°¡ ¹ß»ýÇϰí, ·ÎÄà Ŭ¶óÀÌ¾ðÆ® »ó¿¡¼­ µ¿ÀÛÇÑ´Ù¸é Web Retriever°¡ Á¸ÀçÇÏ´Â Notes Ŭ¶óÀÌ¾ðÆ®°¡ Á¤ÁöµÉ °ÍÀÌ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2003-11.html
http://www.rapid7.com/advisories/R7-0011.html
http://www.kb.cert.org/vuls/id/411489

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Lotus Notes/Domino R4.5 ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®
Lotus Notes/Domino R4.6 ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®
Lotus Notes/Domino R5 ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®
Lotus Notes/Domino R6 º£Å¸ (pre-Gold) ¼­¹ö¿Í Ŭ¶óÀ̾ðÆ®
ÇØ°áÃ¥ Notes R5ÀÇ °æ¿ì¿¡´Â Notes R5.0.12 ¹öÀüÀ¸·Î, R6 pre-Gold ¸±¸®Áî(release)ÀÇ °æ¿ì¿¡´Â ¹öÀü R6.0 Gold ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ¹öÀü R6.0 GoldÀÇ °æ¿ì¿¡´Â ¶Ç ´Ù¸¥ Ãë¾àÁ¡ÀÌ Á¸ÀçÇϱ⠶§¹®¿¡ °¡´ÉÇÑ 2002³â 2¿ù ¸±¸®Áî(release)µÈ Notes R6.0.1 ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ´Â °ÍÀÌ ÁÁ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ¼­¹ö »ó¿¡ Web Retriever ŽºÅ©(task)¸¦ ÁߴܽÃÄÑ¾ß ÇÑ´Ù.
1. ¼­¹öÀÇ NOTES.INI ÆÄÀÏ ¾ÈÀÇ "ServerTasks" ¶óÀο¡¼­ "Web" ¿£Æ®¸®¸¦ »èÁ¦ÇÑ´Ù.
2. ¼­¹ö Äֿܼ¡¼­ "tell web quit" ¸í·ÉÀ» ÀÔ·ÂÇÑ´Ù.

ºÎ°¡ÀûÀ¸·Î, ¸ðµç »ç¿ëÀÚ°¡ Web Retrieval µ¥ÀÌÅͺ£À̽º(/WEB.NSF)¿¡ ¾×¼¼½ºÇÏÁö ¸øÇϵµ·Ï µ¥ÀÌÅͺ£À̽º ÆÄÀÏÀ» »èÁ¦Çϰųª ACLÀ» ÅëÇØ¼­ ¾×¼¼½º ±ÝÁöÇÑ´Ù. Web Retriever°¡ ÁßÁöµÈ °æ¿ì¿¡´Â ÀÌ µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ ¾×¼¼½º°¡ ºÒÇÊ¿äÇÒ °ÍÀÌ´Ù.

¿ÜºÎ ºê¶ó¿ìÀú ´ë½Å Notes À¥ ºê¶ó¿ìÀú¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤µÈ Notes Ŭ¶óÀÌ¾ðÆ® ¶ÇÇÑ ÀÌ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
°ü·Ã URL CVE-2003-0123 (CVE)
°ü·Ã URL 7038 (SecurityFocus)
°ü·Ã URL (ISS)