English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29088
À§Çèµµ 30
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco CatOS´Â Telnet, HTTP, SSH ¼­ºñ½º »óÀÇ TCP-ACK ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡(¹ö±× ID CSCec42751,CSCed45576, CSCed48590)À» °¡Áö°í ÀÖ´Ù.
ÀϺΠCisco CatOS ¹öÀüµéÀÌ Å¾ÀçµÈ µð¹ÙÀ̽ºµé¿¡´Â µð¹ÙÀ̽º »ó¿¡ ¼³Á¤µÈ Telnet, HTTP, SSH ¼­ºñ½º·Î ÀÎÇÏ¿© TCP-ACK ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼º°øÀûÀ¸·Î µµ¿ëµÉ °æ¿ì Cicso CatOS°¡ µ¿ÀÛÇÏ´Â µð¹ÙÀ̽º¸¦ ÀÛµ¿ ÁßÁö(stop)½Ã۰í ÀçºÎÆÃ(reload) ½ÃŰ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. TCP-ACK DoS °ø°ÝÀº 3-way Çڵ彦ÀÌÅ©(handshake)¸¦ ¿Ï¼ºÇϱâ À§ÇØ ¿ä±¸µÇ´Â Á¤»óÀûÀÎ ¸¶Áö¸· ACK ÆÐŶÀ» Àü´ÞÇÏ´Â ´ë½Å, ¿¬°á(connection)ÀÌ ¿Ã¹Ù¸£Áö ¸øÇÑ TCP »óÅ·ΠºüÁöµµ·Ï À߸øµÈ ÀÀ´äÀ» Àü´ÞÇÔÀ¸·Î½á ÀÌ·ç¾îÁø´Ù. ÀÌ °ø°ÝÀº ¿ø°ÝÁöÀÇ Á¶ÀÛµÈ ¼Ò½º(spoofed source)·ÎºÎÅÍ ÃʱâÈ­µÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Catalyst 6000 series, 5000 series, 4500 series, 4000 series
Catalyst 2948G, 2980G, 2980G-A, 4912G - use Catalyst 4000 series code base
Catalyst 2901, 2902, 2926[T,F,GS,GL], 2948 - use Catalyst 5000 series code base
8.xGLX (The earlier 8.xGLX than Cisco CatOS 8.3(2)GLX)
8.x (The earlier than Cisco CatOS 8.2(2))
7.x (The earlier than Cisco CatOS 7.6(6))
6.x (The earlier than Cisco CatOS 6.4(9))
5.x and earlier (The earlier than Cisco CatOS 5.5(20))
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾È(Cisco CatOS Telnet, HTTP and SSH Vulnerability)ÀÇ "Software Versions and Fixes" ¸¦ ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml

¾÷±×·¹À̵åµéÀº Cisco À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.

ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml
°ü·Ã URL (CVE)
°ü·Ã URL 10504 (SecurityFocus)
°ü·Ã URL (ISS)