English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23080
À§Çèµµ 40
Æ÷Æ® 901
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SWAT
»ó¼¼¼³¸í ÇØ´ç SWAT ¼­¹ö´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù.
Samba´Â Samba ¼­¹ö¿¡ ´ëÇÑ ¿ø°Ý °ü¸®¸¦ À§ÇØ »ç¿ëµÇ´Â SWAT(Samba Web Administration Tool)À̶ó´Â À¯Æ¿¸®Æ¼¸¦ ÇÔ²² Á¦°øÇϴµ¥ µðÆúÆ®·Î Æ÷Æ® 901¿¡¼­ root·Î inetd¿¡¼­ ½ÇÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Ù.
HTTP basic ÀÎÁõ µ¿¾È¿¡ Ÿ´çÇÏÁö ¾ÊÀº base64 µ¥ÀÌÅ͸¦ ÇØµ¶Çϱâ À§ÇÑ Samba 3.0.2¿¡¼­ 3.0.4¿¡ ÀÖ´Â SWAT¿¡ ÀÇÇØ »ç¿ëµÇ´Â ³»ºÎ ·çƾÀº Ÿ´çÇÏÁö ¾ÊÀº base64 ¹®ÀÚ¿¡ ÀÇÇÑ ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=bugtraq&m=109052647928375&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=109053195818351&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=109051340810458&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba 3.0.2¿¡¼­ 3.0.4±îÁö
Linux Any version
UNIX Any version
ÇØ°áÃ¥ ´ÙÀ½ Samba À¥ »çÀÌÆ®·ÎºÎÅÍ SambaÀÇ °¡Àå ÃֽйöÀü (3.0.5 ȤÀº 2.2.10 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://samba.org/samba/

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2004:259-23À» ÂüÁ¶ÇÏ¿© sambaÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.redhat.com/support/errata/RHSA-2004-259.html

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.

-- ȤÀº --

½Å·Ú¼º ¾ø´Â ³×Æ®¿öÅ©µé·ÎºÎÅÍ SWAT ¼­ºñ½º(µðÆúÆ®·Î TCP Æ÷Æ® 901)¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Â÷´ÜÇÑ´Ù. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ÇØ´ç /etc/inetd.conf ¶óÀÎÀ» ÁÖ¼®Ã³¸® ÇÏ¿© SWATÀ» »ç¿ë ÁßÁö½ÃŲ´Ù.
°ü·Ã URL CVE-2004-0600 (CVE)
°ü·Ã URL 10780 (SecurityFocus)
°ü·Ã URL (ISS)