English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28638
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í Mozilla/Firefox À¥ ºê¶ó¿ìÀúÀÇ ¹öÀü¿¡ µû¸£¸é ÇØ´ç ¹öÀü¿¡´Â ÀÎÁõ¼­ Çڵ鸵 °ü·Ã ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Mozilla ¿Í Firefox ´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ ¿ÀÇ ¼Ò½º À¥ ºê¶ó¿ìÀúµéÀÌ´Ù. Mozilla 1.7.1°ú ±× ÀÌÀü ¹öÀüµé°ú, Firefox 0.9.2¿Í ±× ÀÌÀü ¹öÀüµé¿¡´Â ÀÎÁõ¼­ °¡Á®¿À±â(Import) °úÁ¤¿¡¼­ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ÀÎÁõ¼­ °¡Á®¿À±â °úÁ¤¿¡¼­ X.509 ÀÎÁõ¼­ÀÇ DN(Distinguished Name)ÀÌ À¯ÀÏÇÔÀ» ¿Ã¹Ù¸£°Ô °Ë»çÇÏÁö ¸øÇϱ⠶§¹®¿¡ ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ë»ó ½Ã½ºÅÛ »ó¿¡ Á¸ÀçÇÏ´Â ·çÆ® CA(certificate authority) ÀÎÁõ¼­¿Í µ¿ÀÏÇÑ DNÀ» °®´Â Àß Á¶ÀÛµÈ ÀÎÁõ¼­·Î ´ë»ó ½Ã½ºÅÛÀÇ ·çÆ® CA¸¦ µ¤¾î¾²±â ÇÔÀ¸·Î½á, Á¤»óÀûÀÎ SSL(Secure Sockets Layer) À¥ »çÀÌÆ®¿¡ Á¢±ÙÇÏÁö ¸øÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/784278
http://securitytracker.com/alerts/2004/Jul/1010714.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Project, Mozilla 1.7.1 ÀÌÇÏ ¹öÀüµé
Mozilla Project, Firefox 0.9.2 ÀÌÇÏ ¹öÀüµé
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ Mozilla FirefoxÀÇ °æ¿ì:
´ÙÀ½ Mozilla Firefox À¥ »çÀÌÆ®·ÎºÎÅÍ FirefoxÀÇ °¡Àå ÃֽйöÀü(0.9.3 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mozilla.org/products/firefox/

Mozilla SuiteÀÇ °æ¿ì:
Mozilla SuiteÀº ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù.

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat º¸¾È ±Ç°í¹® RHSA-2004:421-17 À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-421.html

Gentoo LinuxÀÇ °æ¿ì:
Gentoo Linux º¸¾È ±Ç°í¹® GLSA 200408-22 ¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0758 (CVE)
°ü·Ã URL 10703 (SecurityFocus)
°ü·Ã URL 16706 (ISS)