English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23051
À§Çèµµ 30
Æ÷Æ® 2401
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CVS
»ó¼¼¼³¸í ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ¼­¹ö´Â ÆÄÀÏ Á¶ÀÛ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. CVS (Concurrent Versions System)Àº ´ëºÎºÐÀÇ Linux¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡ Àû¿ë °¡´ÉÇÑ °ø°³ ¼Ò½ºÀÇ ¼Ò½ºÄÚµå °ü¸® ¹× ¹èÆ÷ ½Ã½ºÅÛÀÌ´Ù. CVS ¹öÀü 1.11.9 ÀÌÇÏ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ µð·ºÅ丮¿Í ÆÄÀϵéÀ» »ý¼ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¾ÇÀÇÀûÀÎ ÇüÅÂÀÇ ¸ðµâ ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â CVS Repository¸¦ °¡Áö°í ÀÖ´Â ÆÄÀϽýºÅÛÀÇ Root¿¡ µð·ºÅ丮¿Í ÆÄÀϵéÀ» »ý¼ºÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CVS (Concurrent Versions System) 1.11.9 ÀÌÇÏ
Linux Any version
UNIX Any version
ÇØ°áÃ¥ ´ÙÀ½ CVS À¥ ÆäÀÌÁö¿¡¼­ CVSÀÇ °¡Àå ÃֽйöÀü(1.11.10 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://ftp.gnu.org/non-gnu/cvs/

Slackware LinuxÀÇ °æ¿ì:
´ÙÀ½ slackware-security Mailing List 2003³â 12¿ù 11ÀÏ(¸ñ)ÀÚ ¸ÞÀÏÀ» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2003&m=slackware-security.402538

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2003:112-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:http://www.mandriva.com/en/support/security/advisories/

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Announcement 200312-04¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cvs ¹öÀü(1.11.10 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200312-04.xml

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0977 (CVE)
°ü·Ã URL 9178 (SecurityFocus)
°ü·Ã URL 13929 (ISS)