Ãë¾àÁ¡ID |
27333 |
À§Çèµµ |
40 |
Æ÷Æ® |
53696 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
P2P |
»ó¼¼¼³¸í |
Open DC HubÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â ¿ø°Ý ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Open DC hub´Â Direct Connect ³×Æ®¿öÅ©¸¦ À§ÇÑ Çãºê(Hub) ¼ÒÇÁÆ®¿þ¾îÀÇ Unix/Linux ¹öÀüÀÌ´Ù. Direct Connect´Â Çãºêµé·Î ±¸¼ºµÈ Peer-to-Peer(µ¿µî°£ ȤÀº ´Ü¸»±â°£) ÆÄÀÏ °øÀ¯ ³×Æ®¿öÅ©·Î Çãºê Ŭ¶óÀÌ¾ðÆ®µé³¢¸® Á¢¼ÓÇÒ ¼ö ÀÖ´Ù. Open DC Hub ¹öÀü 0.7.14 ÀÌÇÏÀÇ ¹öÀüµéÀº $RedirectAll ¸í·ÉÀ» ÀûÀýÇÏ°Ô Ã³¸®ÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÑ ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© °ü¸®ÀÚÀÇ ±ÇÇÑÀ¸·Î ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Open DC hubÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/382251 http://www.securityfocus.com/advisories/7565 http://www.linuxsecurity.com/index2.php?option=com_ content&do_pdf=1&id=106940 http://www.securityfocus.com/data/vulnerabilities/exploits/openDCHubBufferOverflowPOC.java
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Joohn, Open DC Hub 0.7.14 ÀÌÇÏÀÇ ¹öÀüµé Unix Any version Linux Any version |
ÇØ°áÃ¥ |
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200411-37À» ÂüÁ¶ÇÏ¿© opendchubÀÇ °¡Àå ÃֽйöÀü(0.7.14-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200411-37.xml
±âŸ ¹èÆ÷ÆÇµé: SourceForge.net À¥ »çÀÌÆ®ÀÎ http://opendchub.sourceforge.net ¿¡¼ ÃֽŹöÀüÀÇ Open DC HubÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-1127 (CVE) |
°ü·Ã URL |
11747 (SecurityFocus) |
°ü·Ã URL |
18254 (ISS) |
|