English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23106
À§Çèµµ 20
Æ÷Æ® 631
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CUPS
»ó¼¼¼³¸í CUPS ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ºó UDP datagramÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Easy Software Products »çÀÇ CUPS(Common UNIX Printing System)Àº "Internet Printing Protocol"¿¡ ±â¹ÝÀ» µÐ UNIX Ç÷§ÆûµéÀ» À§ÇÑ À̱âÁ¾°£ ÇÁ¸°Æ® ÀÛ¾÷ ¼Ö·ç¼ÇÀÌ´Ù. CUPS´Â À¥ ±â¹ÝÀÇ ±×·¡ÇÇÄà ÀÎÅÍÆäÀ̽ºÀ» °¡Áö°í ÀÖÀ¸¸ç ´ëºÎºÐÀÇ Linux ½Ã½ºÅ۵鿡¼­µµ »ç¿ë °¡´ÉÇÏ´Ù. CUPS 1.1.21 ÀÌÀüÀÇ ¹öÀüµéÀº Á¦ÇÑÀûÀÎ ÇüÅÂÀÇ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿µÇâÀ» ¹Þ´Â CUPS ¼­¹ö·Î ºó UDP datagramÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç CUPS ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/9995

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Easy Software Products, CUPS 1.1.21 ÀÌÀüÀÇ ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ CUPS ¼ÒÇÁÆ®¿þ¾î À¥ »çÀÌÆ®ÀÎ http://www.cups.org/software.php ±¸ÇÒ ¼ö ÀÖ´Â CUPSÀÇ °¡Àå ÃֽйöÀü(1.1.21 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Mac OS X and Mac OS X Server 10.3.5ÀÇ °æ¿ì:
´ÙÀ½ AppleCare Knowledge Base Document 61798¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Security Update 2004-09-30À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://docs.info.apple.com/article.html?artnum=61798

Red Hat Desktop ±×¸®°í Red Hat Enterprise Linux AS, ES¿Í WSÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2004:449-17¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ cups package(1.1.17-13.3.13 ȤÀº ÀÌÈÄ)¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-449.html

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:097À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cups ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

Debian GNU/Linux 3.0 (alias woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-545-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cupsys ÆÐŰÁö(1.1.14-5woody6 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-545

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SUSE-SA:2004:031À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ cups ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_31_cups.html

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0558 (CVE)
°ü·Ã URL 11183,11322 (SecurityFocus)
°ü·Ã URL 17389 (ISS)