English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23084
À§Çèµµ 30
Æ÷Æ® 504
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í ÇØ´ç Citadel/UX ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â USER ¸í·É¿¡ ÀÖ´Â ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Citadel/UX´Â ¸Þ½ÃÁö Æ÷·³, Email, äÆÃ, ±×¸®°í ÀνºÅÏÆ® ¸Þ½Ã¡À» Áö¿øÇØ ÁÖ´Â Unix Ç÷§ÆûµéÀ» À§ÇÑ °ø°³ ¼Ò½º ±â¹ÝÀÇ °Ô½ÃÆÇ(BBS) ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Citadel/UX 6.23 ÀÌÇÏÀÇ ¹öÀüµéÀº ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡¿¡ Ãë¾àÇѵ¥ ÀÌ´Â 'USER' ¸í·É Àμöµé¿¡ ´ëÇÑ Ã³¸® °úÁ¤¿¡¼­ÀÇ ºÒÃæºÐÇÑ ±æÀÌ °Ë»ç·Î ÀÎÇØ ¹ß»ýÇÑ´Ù. 504¹ø Æ÷Æ®·Î Á¢¼ÓÇÏ¿© 97 ¹ÙÀÌÆ® ÀÌ»óÀÇ ±æÀ̸¦ °¡Áø USER ¸í·ÉÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ¼­¹ö¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ Citadel/UX ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/370475
http://www.securityfocus.com/archive/1/370611
http://www.securitytracker.com/alerts/2004/Jul/1010809.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Citadel Project, Citadel/UX 6.23 ÀÌÇÏ
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ Citadel ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Citadel/UXÀÇ °¡Àå ÃֽйöÀü(6.24 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://uncensored.citadel.org/citadel/download.php
°ü·Ã URL CVE-2004-1705 (CVE)
°ü·Ã URL 10833 (SecurityFocus)
°ü·Ã URL 16840 (ISS)