Ãë¾àÁ¡ID |
29039 |
À§Çèµµ |
30 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
CISCO |
»ó¼¼¼³¸í |
ÇØ´ç Cisco IOS´Â PPTP ¼ºñ½º°ÅºÎ Ãë¾àÁ¡(Cisco ¹ö±× ID CSCdt46181)À» °¡Áö°í ÀÖ´Ù. PPTP (Point-to-point Tunneling Protocol)´Â ¾ÈÀüÇÏÁö ¾ÊÀº ä³ÎÀ» ÅëÇØ ¾ÈÀüÇÑ ¿ø°Ý Á¢¼Ó ¼ºñ½º¸¦ Á¦°øÇØ ÁÖ±â À§ÇØ °í¾ÈµÈ ÇÁ·ÎÅäÄÝÀÌ´Ù. ÀÌ Ãë¾àÁ¡À» ¹Ýº¹ÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µ¼ÓÀûÀ¸·Î ¼ºñ½º °ÅºÎ (DoS)¸¦ À¯¹ßÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº PPTP ±â´É»Ó¸¸ ¾Æ´Ï¶ó Àüü ¶ó¿ìÅÍÀÇ ±â´ÉÀÌ ¸ØÃç ¹ö¸®°Ô ÇÒ ¼ö ÀÖ´Ù. Á¶ÀÛµÈ PPTP ÆÐŶÀ» Á¦¾î¿ë PPTP Æ÷Æ®ÀÎ 1723 Æ÷Æ®·Î º¸³¿À¸·Î½á ¶ó¿ìÅ͸¦ Å©·¡½¬ ½ÃŰ´Â °ÍÀÌ °¡´ÉÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº Ưº°ÇÑ ¶ó¿ìÅÍ ¼³Á¤À» ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù. PPTP°¡ ÀÛµ¿ÁßÀÎ °Í¸¸À¸·Î Ãë¾àÁ¡ µµ¿ëÀÌ °¡´ÉÇÏ´Ù. ¶ó¿ìÅÍ´Â ´Ü ÇѰ³ÀÇ ÆÐŶÀ» ¹Þ´õ¶óµµ Å©·¡½¬ µÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ´Â Á¤Ã¥ ÆíÁý±â¿¡¼ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html http://www.kb.cert.org/vuls/id/656315
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cisco IOS 12.1E Cisco IOS 12.1EZ Cisco IOS 12.1T Cisco IOS 12.1YA Cisco IOS 12.1YC Cisco IOS 12.1YD Cisco IOS 12.2 Cisco IOS 12.2T Cisco IOS 12.2XA Cisco IOS 12.2XD Cisco IOS 12.2XE Cisco IOS 12.2XH Cisco IOS 12.2XQ |
ÇØ°áÃ¥ |
´ÙÀ½ Cisco º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ Cisco IOS ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html
ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù. |
°ü·Ã URL |
CVE-2001-1183 (CVE) |
°ü·Ã URL |
3022 (SecurityFocus) |
°ü·Ã URL |
6835 (ISS) |
|