Ãë¾àÁ¡ID |
23086 |
À§Çèµµ |
40 |
Æ÷Æ® |
873 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
RSYNCD |
»ó¼¼¼³¸í |
ÇØ´ç rsync ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â µð·ºÅ丮 Ž»ö °áÇÔ¿¡ Ãë¾àÇÏ´Ù. ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ Æ÷ÇԵǾî ÀÖ´Â rsync´Â ¿©·¯ È£½ºÆ®µé °£¿¡ ÆÄÀÏÀ» µ¿±âÈÇϴµ¥ »ç¿ëµÇ´Â ¸Å¿ì ÀαâÀÖ´Â ÅøÀÌ´Ù. ºñ·Ï µðÆúÆ®·Î ÀÛµ¿µÇÁö´Â ¾ÊÁö¸¸ rsync´Â FTP ¹Ì·¯ »çÀÌÆ®·Î ÆÄÀÏ ¹èÆ÷ ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â µ¥¸óÀ¸·Î¼ ÀÛµ¿µÉ ¼ö ÀÖ´Ù. Rsync 2.6.2 ÀÌÇÏ ¹öÀüµé ¿ëÀÇ util.c ÆÄÀÏ ³»ÀÇ sanitize_path ÇÔ¼ö¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº chroot°¡ ÀÛµ¿µÇ°í ÀÖÁö ¾ÊÀ» ¶§, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ rsyncÀÇ ±ÇÇÑÀ¸·Î Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÆÄÀϵéÀ» º¸°Å³ª ¾µ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç rsync ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Aug/1010940.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: GNU Project, rsync 2.6.3 ¹Ì¸¸ UNIX Any version Linux Any version |
ÇØ°áÃ¥ |
rsync ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://samba.org/rsync/download.html ¿¡¼ rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.3 ȤÀº ÀÌÈÄ)ÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ À̸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Security Advisory RHSA-2004:436-07À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2004-436.html
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SuSE-SUSE-SA:2004:026À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_26_rsync.html
Debian GNU/Linux 3.0 (alias woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-538-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö(2.5.5-0.6 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-538
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200408-17À» ÂüÁ¶ÇÏ¿© rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.0-r3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:083À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-0792 (CVE) |
°ü·Ã URL |
10938 (SecurityFocus) |
°ü·Ã URL |
16975 (ISS) |
|