Ãë¾àÁ¡ID |
23080 |
À§Çèµµ |
40 |
Æ÷Æ® |
901 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SWAT |
»ó¼¼¼³¸í |
ÇØ´ç SWAT ¼¹ö´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³´Ù. Samba´Â Samba ¼¹ö¿¡ ´ëÇÑ ¿ø°Ý °ü¸®¸¦ À§ÇØ »ç¿ëµÇ´Â SWAT(Samba Web Administration Tool)À̶ó´Â À¯Æ¿¸®Æ¼¸¦ ÇÔ²² Á¦°øÇϴµ¥ µðÆúÆ®·Î Æ÷Æ® 901¿¡¼ root·Î inetd¿¡¼ ½ÇÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Ù. HTTP basic ÀÎÁõ µ¿¾È¿¡ Ÿ´çÇÏÁö ¾ÊÀº base64 µ¥ÀÌÅ͸¦ ÇØµ¶Çϱâ À§ÇÑ Samba 3.0.2¿¡¼ 3.0.4¿¡ ÀÖ´Â SWAT¿¡ ÀÇÇØ »ç¿ëµÇ´Â ³»ºÎ ·çƾÀº Ÿ´çÇÏÁö ¾ÊÀº base64 ¹®ÀÚ¿¡ ÀÇÇÑ ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=109052647928375&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=109053195818351&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=109051340810458&w=2
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Samba 3.0.2¿¡¼ 3.0.4±îÁö Linux Any version UNIX Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Samba À¥ »çÀÌÆ®·ÎºÎÅÍ SambaÀÇ °¡Àå ÃֽйöÀü (3.0.5 ȤÀº 2.2.10 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://samba.org/samba/
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2004:259-23À» ÂüÁ¶ÇÏ¿© sambaÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.redhat.com/support/errata/RHSA-2004-259.html
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
-- ȤÀº --
½Å·Ú¼º ¾ø´Â ³×Æ®¿öÅ©µé·ÎºÎÅÍ SWAT ¼ºñ½º(µðÆúÆ®·Î TCP Æ÷Æ® 901)¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Â÷´ÜÇÑ´Ù. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ÇØ´ç /etc/inetd.conf ¶óÀÎÀ» ÁÖ¼®Ã³¸® ÇÏ¿© SWATÀ» »ç¿ë ÁßÁö½ÃŲ´Ù. |
°ü·Ã URL |
CVE-2004-0600 (CVE) |
°ü·Ã URL |
10780 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|