English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23086
À§Çèµµ 40
Æ÷Æ® 873
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù RSYNCD
»ó¼¼¼³¸í ÇØ´ç rsync ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â µð·ºÅ丮 Ž»ö °áÇÔ¿¡ Ãë¾àÇÏ´Ù. ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ Æ÷ÇԵǾî ÀÖ´Â rsync´Â ¿©·¯ È£½ºÆ®µé °£¿¡ ÆÄÀÏÀ» µ¿±âÈ­Çϴµ¥ »ç¿ëµÇ´Â ¸Å¿ì ÀαâÀÖ´Â ÅøÀÌ´Ù. ºñ·Ï µðÆúÆ®·Î ÀÛµ¿µÇÁö´Â ¾ÊÁö¸¸ rsync´Â FTP ¹Ì·¯ »çÀÌÆ®·Î ÆÄÀÏ ¹èÆ÷ ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â µ¥¸óÀ¸·Î¼­ ÀÛµ¿µÉ ¼ö ÀÖ´Ù.
Rsync 2.6.2 ÀÌÇÏ ¹öÀüµé ¿ëÀÇ util.c ÆÄÀÏ ³»ÀÇ sanitize_path ÇÔ¼ö¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº chroot°¡ ÀÛµ¿µÇ°í ÀÖÁö ¾ÊÀ» ¶§, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ rsyncÀÇ ±ÇÇÑÀ¸·Î Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÆÄÀϵéÀ» º¸°Å³ª ¾µ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç rsync ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2004/Aug/1010940.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
GNU Project, rsync 2.6.3 ¹Ì¸¸
UNIX Any version
Linux Any version
ÇØ°áÃ¥ rsync ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://samba.org/rsync/download.html ¿¡¼­ rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.3 ȤÀº ÀÌÈÄ)ÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ À̸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2004:436-07À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-436.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SuSE-SUSE-SA:2004:026À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_26_rsync.html

Debian GNU/Linux 3.0 (alias woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-538-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö(2.5.5-0.6 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-538

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200408-17À» ÂüÁ¶ÇÏ¿© rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.0-r3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:083À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-0792 (CVE)
°ü·Ã URL 10938 (SecurityFocus)
°ü·Ã URL 16975 (ISS)