English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23064
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â ISS BlackICEÀÇ ¹öÀü¿¡ µû¸£¸é Á¦Ç°Àº PAM ±¸¼º¿ä¼ÒµéÀ» ÅëÇÑ ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οìµé¿¡ Ãë¾àÇÏ´Ù.
ISS BlackICE´Â Windows ¿î¿µÃ¼Á¦¿ëÀÇ °³ÀÎ ¹æÈ­º®/IDS ÀÌ´Ù. ¸î¸î ¿ø°ÝÀÇ Ãë¾àÁ¡µéÀÌ ÀÌ Á¦Ç°¿¡¼­ ¹ß°ßµÇ¾ú´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ¹æÈ­º®/IDS ¼­ºñ½º¸¦ ¸ØÃß°Ô Çϰųª ¿µÇâÀ» ¹Þ´Â È£½ºÆ®»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
PAM (Protocol Analysis Module)Àº ºÐ¼®°ú °ø°Ý ŽÁö¸¦ ¼öÇàÇϱâ À§ÇÏ¿© ³×Æ®¿öÅ© ÇÁ·ÎÅäÄݵéÀÇ ÆÄ½Ì(parsing)À» °¡´ÉÇÏ°Ô ÇØ ÁØ´Ù. ¹®Á¦µéÀº PAM ±¸¼º¿ä¼Ò¿¡ ÀÇÇØ Á¦°øµÇ´Â SMB¿Í ICQ ÆÄ½Ì ·çƾµé¿¡ Á¸ÀçÇÑ´Ù. ƯÈ÷, Witty ¿úÀº ISS Á¦Ç°µé¿¡ ÀÖ´Â ICQ ÆÄ½Ì Ãë¾àÁ¡µéÀ» ÅëÇÏ¿© ÀüÆÄµÇ°í ÀÖ´Ù. BlackICE PC Protection Á¦Ç°ÀÇ ÆÐÄ¡µÇÁö ¾ÊÀº ¹öÀüµéÀº °¨¿°µÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/150326
http://www.kb.cert.org/vuls/id/947254


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
ISS, Inc. BlackICE Agent for Server 3.6 ecf ÀÌÇÏ
ISS, Inc. BlackICE PC Protection 3.6 ccf ÀÌÇÏ
ISS, Inc. BlackICE Server Protection 3.6 ccf ÀÌÇÏ
ISS, Inc. RealSecure Desktop 3.6 ecf ÀÌÇÏ
ISS, Inc. RealSecure Desktop 7.0 ebl ÀÌÇÏ
ISS, Inc. RealSecure Guard 3.6 ecf ÀÌÇÏ
ISS, Inc. RealSecure Network Sensor 7.0 XPU 22.4 - 22.10
ISS, Inc. RealSecure Sentry 3.6 ecf ÀÌÇÏ
ISS, Inc. RealSecure Server Sensor 7.0 XPU 22.4 to 22.1
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ ISS ´Ù¿î·Îµå ¼¾ÅÍÀÎ http://www.iss.net/download/ ·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â ¾Æ·¡¿¡ ³ª¿Í ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ XPU·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:

RealSecure Network 7.0, XPU 22.12
RealSecure Server Sensor 7.0 XPU 22.12
Proventia A Series XPU 22.12
Proventia G Series XPU 22.12
Proventia M Series XPU 1.10
RealSecure Desktop 7.0 ebm
RealSecure Desktop 3.6 ecg
RealSecure Guard 3.6 ecg
RealSecure Sentry 3.6 ecg
BlackICE Agent for Server 3.6 ecg
RealSecure Server Sensor 6.5 for Windows SR 3.11
BlackICE PC Protection 3.6 ccg
BlackICE Server Protection 3.6 ccg
°ü·Ã URL CVE-2000-0562,CVE-2002-0237,CVE-2002-0956,CVE-2002-0957,CVE-2004-0193,CVE-2004-0362 (CVE)
°ü·Ã URL 4025,4950,9513,9514,9752,9913 (SecurityFocus)
°ü·Ã URL 15207,15442,15543 (ISS)