English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23089
À§Çèµµ 30
Æ÷Æ® 139
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Samba
»ó¼¼¼³¸í ÇØ´ç Samba ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö¿¡´Â ´ÙÁßÀÇ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
Samba´Â SMB/CIFS Ŭ¶óÀÌ¾ðÆ®µé¿¡°Ô ¾çÁúÀÇ ÆÄÀÏ ¹× ÇÁ¸°Æ® ¼­ºñ½ºµéÀ» Á¦°øÇØ ÁÖ´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¹«·á ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Samba 3.0.7 ÀÌÀüÀÇ ¹öÀüµéÀº ASN.1 ±×¸®°í MailSlot ÆÐŶµéÀ» ÇØ¼®ÇÏ´Â ºÎºÐ¿¡¼­ÀÇ ¿À·ù¿¡ ÀÇÇÑ ´ÙÁßÀÇ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ºñÀΰ¡µÈ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ¼­¹ö¿¡ ÀÎÁõ ¿äû ½Ã Àß Á¶ÀÛµÈ ASN.1 ÆÐŶÀ» º¸³¿À¸·Î½á ÀÚ¿ø °í°¥ °ø°ÝÀ» ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» ¹Ýº¹ÀûÀ¸·Î »ç¿ëÇÔÀ¸·Î½á Èñ»ýÀÚÀÇ ¼­¹ö¿¡ ÀÖ´Â ¸ðµç ÀÚ¿øµéÀÌ °í°¥µÇµµ·Ï ÇÏ¿© ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù. ¶Ç ´Ù¸¥ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ºñÁ¤»óÀûÀÎ NetBIOS ÆÐŶÀ» º¸³¿À¸·Î½á nmbd ÇÁ·Î¼¼½º¸¦ Å©·¡½¬(Crash) ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Samba ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba Project, Samba 3.0.7 ÀÌÀü ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ Samba À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SambaÀÇ °¡Àå ÃֽйöÀü(3.0.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://us4.samba.org/samba/history/samba-3.0.7.html

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200409-16À» ÂüÁ¶ÇÏ¿© SambaÀÇ °¡Àå ÃֽйöÀü(3.0.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200409-16.xml

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:092¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Samba ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0807,CVE-2004-0808 (CVE)
°ü·Ã URL 11156 (SecurityFocus)
°ü·Ã URL 17325,17326 (ISS)