English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29039
À§Çèµµ 30
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS´Â PPTP ¼­ºñ½º°ÅºÎ Ãë¾àÁ¡(Cisco ¹ö±× ID CSCdt46181)À» °¡Áö°í ÀÖ´Ù. PPTP (Point-to-point Tunneling Protocol)´Â ¾ÈÀüÇÏÁö ¾ÊÀº ä³ÎÀ» ÅëÇØ ¾ÈÀüÇÑ ¿ø°Ý Á¢¼Ó ¼­ºñ½º¸¦ Á¦°øÇØ ÁÖ±â À§ÇØ °í¾ÈµÈ ÇÁ·ÎÅäÄÝÀÌ´Ù. ÀÌ Ãë¾àÁ¡À» ¹Ýº¹ÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µ¼ÓÀûÀ¸·Î ¼­ºñ½º °ÅºÎ (DoS)¸¦ À¯¹ßÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº PPTP ±â´É»Ó¸¸ ¾Æ´Ï¶ó Àüü ¶ó¿ìÅÍÀÇ ±â´ÉÀÌ ¸ØÃç ¹ö¸®°Ô ÇÒ ¼ö ÀÖ´Ù.
Á¶ÀÛµÈ PPTP ÆÐŶÀ» Á¦¾î¿ë PPTP Æ÷Æ®ÀÎ 1723 Æ÷Æ®·Î º¸³¿À¸·Î½á ¶ó¿ìÅ͸¦ Å©·¡½¬ ½ÃŰ´Â °ÍÀÌ °¡´ÉÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº Ưº°ÇÑ ¶ó¿ìÅÍ ¼³Á¤À» ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù. PPTP°¡ ÀÛµ¿ÁßÀÎ °Í¸¸À¸·Î Ãë¾àÁ¡ µµ¿ëÀÌ °¡´ÉÇÏ´Ù. ¶ó¿ìÅÍ´Â ´Ü ÇѰ³ÀÇ ÆÐŶÀ» ¹Þ´õ¶óµµ Å©·¡½¬ µÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html
http://www.kb.cert.org/vuls/id/656315

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco IOS 12.1E
Cisco IOS 12.1EZ
Cisco IOS 12.1T
Cisco IOS 12.1YA
Cisco IOS 12.1YC
Cisco IOS 12.1YD
Cisco IOS 12.2
Cisco IOS 12.2T
Cisco IOS 12.2XA
Cisco IOS 12.2XD
Cisco IOS 12.2XE
Cisco IOS 12.2XH
Cisco IOS 12.2XQ
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ Cisco IOS ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html

ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.
°ü·Ã URL CVE-2001-1183 (CVE)
°ü·Ã URL 3022 (SecurityFocus)
°ü·Ã URL 6835 (ISS)