English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23031
À§Çèµµ 40
Æ÷Æ® 631
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CUPS
»ó¼¼¼³¸í ÇØ´ç CUPS ¼­¹ö´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¼­¹ö¸¦ ¼Ë´Ù¿î ½ÃŰ°Å³ª ½ÉÁö¾î 'lp' »ç¿ëÀÚÀÇ ±ÇÇÑÀ» ¿ø°ÝÀ¸·Î ¾ò¾î³¾ ¼ö ÀÖ´Â ´Ù¾çÇÑ °áÇÔÀ» °¡Áö°í ÀÖ´Ù.
Easy Software ProductsÀÇ CUPS(Common Unix Printing System)Àº ¿©·¯ À¯´Ð½º ȯ°æ¿¡¼­ »ç¿ëµÇ´Â Ç÷§Æû ÇÁ¸°ÆÃ ¼Ö·ç¼ÇÀÌ´Ù. "Internet Printing Protocol"¿¡ ±â¹ÝÀ» µÎ¸ç, ´ëºÎºÐÀÇ PostScript¿Í ·¹ÀÌÀú ÇÁ¸°Å͵鿡 ¿ÏÀüÇÑ ÇÁ¸°ÆÃ ¼­ºñ½º¸¦ Áö¿øÇÑ´Ù. CUPS´Â ÇÁ¸°ÅÍ °ü¸®¸¦ À§ÇÑ À¥ ±â¹ÝÀÇ ±×·¡ÇÇÄà ÀÎÅÍÆäÀ̽º¸¦ °¡Áö¸ç ´ëºÎºÐÀÇ Linux ½Ã½ºÅÛ¿¡¼­ »ç¿ëÀÌ °¡´ÉÇÏ´Ù.
·ÎÄà ȤÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº Ãë¾àÇÑ CUPS ¹öÀüµé¿¡ ÀÖ´Â ´Ù¾çÇÑ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© root ȤÀº lp ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* ¾Ë¸²: Å©·¡½¬°¡ ¹ß»ýÇÑ CUPS µ¥¸óÀº Á¤»ó ÀÛµ¿À» À§ÇÏ¿© Àç½ÃÀÛ ½ÃÄÑ¾ß ÇÑ´Ù. ¸¸¾à µ¥¸óÀÌ Àç½ÃÀÛÇÏÁö ¾Ê´Â´Ù¸é ´ÙÀ½ ÆÄÀϵéÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇϰí ÀÖÀ¸¸é »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù:
/var/spool/cups/d00*-0*
/var/spool/cups/c00*

* ÀÌ Ãë¾àÁ¡µé°ú °ü·ÃÇÑ CVE ¸µÅ©µé:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1366
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1367
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1368
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1369
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1371
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1372
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1383
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1384

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Common Unix Printing System (CUPS) 1.1.14 ¿¡¼­ 1.1.17 ±îÁö
Apple Computer Inc.
Debian Project
FreeBSD Project
MandrakeSoft Inc.
NetBSD Foundation
Red Hat Inc.
Slackware Linux Inc.
SuSE Inc.
The SCO Group
Turbolinux Inc.
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© CUPSÀÇ °¡Àå ÃֽйöÀü (1.1.18 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cups.org/
°ü·Ã URL CVE-2002-1366 (CVE)
°ü·Ã URL 6435 (SecurityFocus)
°ü·Ã URL 10907 (ISS)