English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23050
À§Çèµµ 40
Æ÷Æ® 2401
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CVS
»ó¼¼¼³¸í ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ¼­¹ö´Â °ø°ÝÀÚ°¡ Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ´ëÇØ ShellÀ» ȹµæÇÒ ¼ö ÀÖ´Â Double Free() Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
CVS (Concurrent Versions System)Àº ´ëºÎºÐÀÇ Linux¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡ Àû¿ë °¡´ÉÇÑ °ø°³ ¼Ò½ºÀÇ ¼Ò½ºÄÚµå °ü¸® ¹× ¹èÆ÷ ½Ã½ºÅÛÀÌ´Ù. CVS ¹öÀü 1.11.4 ÀÌÇÏ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ µ¿ÀûÀ¸·Î ÇÒ´çµÈ ¸Þ¸ð¸® ¼¼±×¸ÕÆ®µéÀÌ µÎ¹ø ÇÒ´çÇØÁ¦ µÇµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á, Ãë¾àÇÑ CVS ¼­¹ö¿¡ ´ëÇÑ À͸íÀÇ Àб⠱ÇÇÑÀ» °¡Áø ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÓÀÇÀÇ ÄÚµåÀÇ ½ÇÇà, ¼­¹ö ÇÁ·Î±×·¥ ÀÛµ¿ÀÇ ±³¶õ, Áß¿äÇÑ Á¤º¸ Àбâ, ¼­ºñ½º °ÅºÎ °ø°Ý À¯¹ß µîÀ» À̲ø¾î ³¾ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2003-02.html
http://www.kb.cert.org/vuls/id/650937
http://archives.neohapsis.com/archives/bugtraq/2003-01/0262.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CVS (Concurrent Versions System) 1.11.4 ÀÌÇÏ
Linux Any version
UNIX Any version
ÇØ°áÃ¥ ´ÙÀ½ CVS À¥ ÆäÀÌÁö¿¡¼­ CVSÀÇ °¡Àå ÃֽйöÀü(1.11.5 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://ftp.gnu.org/non-gnu/cvs/

FreeBSDÀÇ °æ¿ì:
´ÙÀ½ FreeBSD»ç Security Advisory FreeBSD-SA-03:01.cvs¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù:
http://www.linuxsecurity.com/content/view/104580/170/

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2003:012-09¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ CVS ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://rhn.redhat.com/errata/RHSA-2003-012.html

Debian GNU/LinuxÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-233-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-233

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SuSE-SA:2003:0007À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2003_007_cvs.html

Sun Linux 5.0.3ÀÇ °æ¿ì:
´ÙÀ½ Sun Alert Notification 50439¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ÆÐŰÁö(1.11.1p1-8.7 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1000021.1

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Announcement 200301-12¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ¹öÀü(cvs-1.11.5r ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/104530/170/

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT Advisory CA-2003-02¸¦ ÂüÁ¶ÇÑ´Ù:
http://www.cert.org/advisories/CA-2003-02.html
°ü·Ã URL CVE-2003-0015 (CVE)
°ü·Ã URL 6650 (SecurityFocus)
°ü·Ã URL 11108 (ISS)