Ãë¾àÁ¡ID |
29076 |
À§Çèµµ |
40 |
Æ÷Æ® |
5060 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
Protocol |
»ó¼¼¼³¸í |
ÇØ´ç SIP Express RouterÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â SIP INVITE ¸Þ¼¼Áö¸¦ ÅëÇÑ ´ÙÁß ¼ºñ½º °ÅºÎ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. SIP (Session Initiation Protocol)´Â Voice over IP (VoIP), ÀÎÅÍ³Ý È¸ÀÇ, ÀüÈ, À̺¥Æ® ¾Ë¸², ÀνºÅÏÆ® ¸Þ½Ã¡, ±×¸®°í ´Ù¾çÇÑ ´Ù¸¥ ¾îÇø®ÄÉÀ̼ǵ鿡¼ °øÅëÀûÀ¸·Î »ç¿ëµÇ´Â °³¹ß ÁøÇà ÁßÀÌ¸é¼ »õ·Ó°Ô äÅõǰí ÀÖ´Â ÇÁ·ÎÅäÄÝ(±Ô¾à)ÀÌ´Ù. SIP´Â »ç¿ëÀڵ鰣¿¡ Åë½Å°ú µ¥ÀÌÅÍ ¼¼¼ÇµéÀ» ¸Î±â À§ÇÑ ÅØ½ºÆ® ±â¹ÝÀÇ ÇÁ·ÎÅäÄÝÀÌ´Ù. SIP Express Router (ser)´Â °í¼º´ÉÀÇ À籸¼º °¡´ÉÇÑ ¹«·á·Î »ç¿ëÇÒ ¼ö ÀÖ´Â SIP ¼¹öÀÌ´Ù. SIP Express Router (ser)ÀÇ 0.8.10 ¹Ì¸¸ÀÇ ¹öÀüµéÀº SIP INVITE ¸Þ½ÃÁöÀÇ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇØ ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº Oulu ´ëÇб³ Secure Programming Group (OUSPG)¿¡ ÀÇÇØ °³¹ßµÈ PROTOS C07-SIP Test-SuiteÀ» ÀÌ¿ëÇÏ¿© ¹ß°ßµÇ¾ú´Ù. ¸¹Àº º¥´õÀÇ ±¸ÇöµéÀÌ ÀÌ Ãë¾àÁ¡µé¿¡ Ãë¾àÇϸç ÀÌ Ãë¾àÁ¡µéÀº ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÑ Àåºñµé¿¡ ¼ºñ½º °ÅºÎ¸¦ À¯¹ßÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ¸î¸î ȯ°æ ÇÏ¿¡¼´Â Àåºñµé¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º±îÁöµµ °¡´ÉÇÑ °ÍÀ¸·Î º¸°íµÇ¾î ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç SIP Express RouterÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/528719 http://www.cert.org/advisories/CA-2003-06.html http://www.securitytracker.com/alerts/2003/Feb/1006167.html http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cisco IP Phone Model 4.2 ÀÌÀüÀÇ SIP images¸¦ °¡Áø 7940/7960 Cisco IP Phone SIP Images P0S3-04-2-00 ¹× ÀÌÈÄ ¹öÀüµé Cisco Secure PIX Firewall 5.2(9), 6.0(4), 6.1(4), ±×¸®°í 6.2(2) ¹× ÀÌÈÄ ¹öÀüµé Cisco IOS fixeµéÀ» Æ÷ÇÔÇÑ 12.2(11)T3 ±×¸®°í 12.2(13)T1 IPTel IPTel SIP Express Router (ser) 0.8.9 ¹× ÀÌÀü ¹öÀüµé Nortel Networks Nortel Succession Communication Server 2000 Nortel Networks Nortel Succession Communication Server 2000 - Compact |
ÇØ°áÃ¥ |
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, °ø°ÝÀÚµéÀÌ ³×Æ®¿öÅ©ÀÇ ¿ÜºÎ¿¡¼ ¸í½ÃÀûÀ¸·Î SIP ¼ºñ½º¸¦ Á¦°øÇØ ÁÖµµ·Ï Àΰ¡¹ÞÁö ¾ÊÀº ·ÎÄà ³×Æ®¿öÅ©¿¡ ÀÖ´Â Ãë¾àÇÑ ÀåºñµéÀ» ¾×¼¼½ºÇÏÁö ¸øÇϵµ·Ï ´ÙÀ½°ú °°Àº Æ÷Æ®µé¿¡ ´ëÇØ ÀÎÀÔ ÇÊÅ͸µÀ» ½Ç½ÃÇÏ¿©¾ß ÇÑ´Ù: sip 5060/udp # Session Initiation Protocol (SIP) sip 5060/tcp # Session Initiation Protocol (SIP) sip 5061/tcp # Session Initiation Protocol (SIP) over TLS
Cisco IP Phone Model 4.2 ÀÌÀüÀÇ SIP images¸¦ °¡Áø 7940/7960ÀÇ °æ¿ì: Cisco IP Phone SIP Images P0S3-04-2-00 ¹× ÀÌÈÄ ¹öÀüµéÀÇ °æ¿ì: Cisco Secure PIX Firewall 5.2(9), 6.0(4), 6.1(4), ±×¸®°í 6.2(2) ¹× ÀÌÈÄ ¹öÀüµéÀÇ °æ¿ì: Cisco IOS fixeµéÀ» Æ÷ÇÔÇÑ 12.2(11)T3 ±×¸®°í 12.2(13)T1ÀÇ °æ¿ì: ´ÙÀ½ Cisco Security Advisory 2003³â 2¿ù 21ÀÏÀÚ¸¦ ÂüÁ¶ÇÏ¿© Cisco SoftwareÀÇ °¡Àå ÃÖ½ÅÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
IPTel SIP Express Router 0.8.9 ¹× ÀÌÈÄ ¹öÀüµéÀÇ °æ¿ì: ´ÙÀ½ iptel.org À¥ »çÀÌÆ®¿¡¼ °¡Àå ÃÖ½ÅÀÇ Æß¿þ¾î ¹öÀü(0.8.10 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.iptel.org/
±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº¸°Å³ª CERT Vulnerability Note VU#528719ÀÎ http://www.kb.cert.org/vuls/id/528719 À» ÂüÁ¶ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
6904 (SecurityFocus) |
°ü·Ã URL |
11379 (ISS) |
|