Ãë¾àÁ¡ID |
29040 |
À§Çèµµ |
40 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
CISCO |
»ó¼¼¼³¸í |
ÇØ´ç Cisco IOS´Â ºñÁ¤»óÀûÀÎ SIP ÆÐŶµéÀ» ÅëÇÑ ¼ºñ½º°ÅºÎ Ãë¾àÁ¡(CISCO ¹ö±× ID CSCdz39284¿Í CSCdz41124)À» °¡Áö°í ÀÖ´Ù. Oulu ´ëÇб³ º¸¾È ÇÁ·Î±×·¡¹Ö ±×·ìÀº SIP (Session Initiation Protocol) ±¸Çöµé¿¡¼ ¸¹Àº Ãë¾àÁ¡µéÀ» ¹ß°ßÇß´Ù. ÀÌ ¹®Á¦µéÀº ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÑ Àåºñµé¿¡¼ ¼ºñ½º°ÅºÎ¸¦ À¯¹ßÇÏ´Â µ¥¿¡ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ¾î¶² ƯÁ¤ Á¶°Çµé¿¡¼´Â Àåºñµé¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º°¡ °¡´ÉÇÑ °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖ´Ù.
SIP´Â IP¸¦ ÅëÇÑ ¸ÖƼ¹Ìµð¾î ȸÀǸ¦ À§ÇÑ Internet Engineering Task Force (IETF) Ç¥ÁØÀÌ´Ù. SIP´Â µÎ°³ ÀÌ»óÀÇ Á¾´Ü°£¿¡ È£Ãâ(call)µéÀ» ¸Î°Å³ª, À¯ÁöÇϰųª, Á¾·áÇÏ´Â µ¥¿¡ »ç¿ëµÉ ¼ö ÀÖ´Â (RFC 2543°ú 3261¿¡ Á¤ÀǵÈ) ASCII ±â¹Ý, ¾îÇø®ÄÉÀÌ¼Ç °èÃþÀÇ Á¦¾î ÇÁ·ÎÅäÄÝÀÌ´Ù.
12.2T train ȤÀº 12.2 'X' trainµéÀÇ Cisco IOS ¹öÀüµéÀÌ °¡µ¿µÇ´Â ÀåºñµéÀº SIP ÇʵåµéÀÇ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇØ ¸®ºÎÆÃ(reset) µÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº Cisco ¹ö±× ID CSCdz39284¿Í CSCdz41124¿¡ ¹®¼ÈµÇ¾î ÀÖ´Ù. CSCdz39284¿¡ Ãë¾àÇÑ Á¶°ÇÀ¸·Î´Â Àåºñ¿¡ Ãë¾àÇÑ ¹öÀüÀÇ IOS ¹öÀüÀÌ °¡µ¿ÁßÀÌ¸é¼ SIP °ÔÀÌÆ®¿þÀ̷μ ¼³Á¤µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. ¶ÇÇÑ NAT¸¦ ¼öÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Â Ãë¾àÇÑ ¹öÀüÀÇ Cisco IOS°¡ °¡µ¿µÇ´Â ÀåºñµéÀÌ SIP°¡ Àü¼ÛÀ» À§ÇØ UDP¸¦ »ç¿ëÇÑ´Ù¸é CSCdz41124¿¡ Ãë¾àÇÏ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ´Â Á¤Ã¥ ÆíÁý±â¿¡¼ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml http://www.cert.org/advisories/CA-2003-06.html http://www.kb.cert.org/vuls/id/528719 http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/ http://www.securitytracker.com/alerts/2003/Feb/1006167.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cisco IOS 12.2T Cisco IOS 12.2X |
ÇØ°áÃ¥ |
´ÙÀ½ Cisco º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© Cisco IOSÀÇ °¡Àå ÃֽйöÀü (12.2(11)T3 ȤÀº 12.2(13)T1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/sw-center/ ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â ¸¸¾à SIP ÇÁ·ÎÅäÄÝÀ» À§ÇØ NAT°¡ ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é, ÀϹÝÀûÀÎ NAT ¼ºñ½ºµéÀ» ¼öÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Â Cisco IOSÀÇ Ãë¾àÇÑ ¹öÀüµéÀ» °¡µ¿ÁßÀÎ ÀåºñµéÀº 5060ÀÇ Ãâ¹ßÁö ȤÀº ¸ñÀûÁö Æ÷Æ®µéÀ» ¾²´Â UDP Æ®·¡ÇÈÀ» Â÷´ÜÇÔÀ¸·Î½á SIP Æ®·¡ÇÈÀÌ NAT º¯È¯ÀÌ µÇÁö ¾Êµµ·Ï ÇØ ÁÖ´Â Á¢±Ù¸ñ·Ï(Access List)À» °£´ÜÇÏ°Ô ±¸ÇöÇÒ ¼ö ÀÖ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
6904 (SecurityFocus) |
°ü·Ã URL |
11379 (ISS) |
|