English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23038
À§Çèµµ 40
Æ÷Æ® 139
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Samba
»ó¼¼¼³¸í ÇØ´ç Samba ¼­¹ö´Â trans2open ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Samba´Â SMB/CIFS Ŭ¶óÀÌ¾ðÆ®µé¿¡°Ô ¾çÁúÀÇ ÆÄÀÏ ¹× ÇÁ¸°Æ® ¼­ºñ½ºµéÀ» Á¦°øÇØ ÁÖ´Â °ø°³ ¼Ò½º/¹«·á ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Samba-TNG´Â ¿ø·¡ Samba·ÎºÎÅÍ ¶³¾îÁ® °ç°¡Áö·Î À©µµ¿ìÁî NT µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¸¦ ´ëüÇÏ´Â ¸ñÀûÀ¸·Î »ç¿ëµÈ´Ù.
Digital Defense »ç´Â Samba SMB/CIFS ¼­¹ö¿¡ ÀÖ´Â ½É°¢ÇÑ Ãë¾àÁ¡À» Samba ÆÀ¿¡ ¾Ë·È´Ù. ¶ÇÇÑ ÀÌ ¿ø º¸°í¼­¿¡ ´ëÇÑ ÀÀ´ä¿¡ Samba ÆÀ¿¡ ÀÇÇÑ ³»ºÎ ÄÚµå °ËÁõ¿¡ ÀÇÇØ Ãß°¡ÀûÀÎ ¹öÆÛ ¿À¹öÇ÷οìµéÀÌ ¹ß°ßµÇ¾ú´Ù. ÀÌ Ãë¾àÁ¡µéÀº À͸í(anonymous)ÀÇ »ç¿ëÀÚ°¡ Samba¸¦ ¼­ºñ½ºÇÏ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ root ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ µµ¿ë ÇÁ·Î±×·¥Àº ÀÌ¹Ì ÁÖÀ§¿¡¼­ »ç¿ëµÇ°í ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/317615

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba prior to 2.2.8a
Samba 2.0 prior to 2.0.10
Samba-TNG prior to 0.3.2
ÇØ°áÃ¥ Samba ¹öÀü 2.2.8a °ú Samba-TNG ¹öÀü 0.3.2Àº Ãë¾àÇÏÁö ¾Ê´Ù. Samba 2.0À» À§ÇÑ fix ¸¸ÀÌ Samba°¡ Á¦°øÇÏ´Â ÆÐÄ¡°¡ µÈ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î Samba 2.2.8 ¼Ò½º Äڵ忡¼­ smbd/trans2.c ¿¡ ÀÖ´Â ¶óÀÎ 250¿¡¼­ ¹ß°ßµÇ´Â StrnCpy ¶óÀÎÀ» ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÏ´Â ¹æ¹ýÀÌ ÀÖ´Ù:

-StrnCpy(fname,pname,namelen);
+StrnCpy(fname,pname,MIN(namelen, sizeof(fname)-1));

-- ȤÀº --

´ÙÀ½ »çÀÌÆ®µéÀ» ÂüÁ¶ÇÏ¿© Samba (2.2.8a ÀÌ»ó) ȤÀº Samba-TNG (0.3.2 ÀÌ»ó)ÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
Samba ´Ù¿î·Îµå: http://www.samba.org/
Samba-TNG ´Ù¿î·Îµå: http://www.samba-tng.org/

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2003:137-01À» Âü°íÇÏ¿© ¾Æ·¡¿¡ ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.redhat.com/support/errata/RHSA-2003-137.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È ±Ç°í¾È SuSE-SA:2003:025À» ÂüÁ¶ÇÏ¿© SambaÀÇ ¾÷µ¥ÀÌÆ®µÈ ÆÐŰÁö¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
http://www.securityfocus.com/archive/1/317690

Mandrake LinuxÀÇ °æ¿ì:
Mandrake º¸¾È ±Ç°í¾È MDKSA-2003:044À» ÂüÁ¶ÇÏ¿© ¾÷µ¥ÀÌÆ®µÈ Samba ÆÐŰÁö¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.securityfocus.com/archive/1/317707

Debian GNU/Linux 2.2, 3.0ÀÇ °æ¿ì:
´ÙÀ½ DebianÀÇ º¸¾È ±Ç°í¾È DSA-280-1À» ÂüÁ¶ÇÏ¿© SambaÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-280

±âŸ:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0196,CVE-2003-0201 (CVE)
°ü·Ã URL 7294,7295 (SecurityFocus)
°ü·Ã URL (ISS)