Ãë¾àÁ¡ID |
29088 |
À§Çèµµ |
30 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
CISCO |
»ó¼¼¼³¸í |
ÇØ´ç Cisco CatOS´Â Telnet, HTTP, SSH ¼ºñ½º »óÀÇ TCP-ACK ¼ºñ½º °ÅºÎ Ãë¾àÁ¡(¹ö±× ID CSCec42751,CSCed45576, CSCed48590)À» °¡Áö°í ÀÖ´Ù. ÀϺΠCisco CatOS ¹öÀüµéÀÌ Å¾ÀçµÈ µð¹ÙÀ̽ºµé¿¡´Â µð¹ÙÀ̽º »ó¿¡ ¼³Á¤µÈ Telnet, HTTP, SSH ¼ºñ½º·Î ÀÎÇÏ¿© TCP-ACK ¼ºñ½º °ÅºÎ °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¼º°øÀûÀ¸·Î µµ¿ëµÉ °æ¿ì Cicso CatOS°¡ µ¿ÀÛÇÏ´Â µð¹ÙÀ̽º¸¦ ÀÛµ¿ ÁßÁö(stop)½Ã۰í ÀçºÎÆÃ(reload) ½ÃŰ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. TCP-ACK DoS °ø°ÝÀº 3-way Çڵ彦ÀÌÅ©(handshake)¸¦ ¿Ï¼ºÇϱâ À§ÇØ ¿ä±¸µÇ´Â Á¤»óÀûÀÎ ¸¶Áö¸· ACK ÆÐŶÀ» Àü´ÞÇÏ´Â ´ë½Å, ¿¬°á(connection)ÀÌ ¿Ã¹Ù¸£Áö ¸øÇÑ TCP »óÅ·ΠºüÁöµµ·Ï À߸øµÈ ÀÀ´äÀ» Àü´ÞÇÔÀ¸·Î½á ÀÌ·ç¾îÁø´Ù. ÀÌ °ø°ÝÀº ¿ø°ÝÁöÀÇ Á¶ÀÛµÈ ¼Ò½º(spoofed source)·ÎºÎÅÍ Ãʱâ鵃 ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ´Â Á¤Ã¥ ÆíÁý±â¿¡¼ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Catalyst 6000 series, 5000 series, 4500 series, 4000 series Catalyst 2948G, 2980G, 2980G-A, 4912G - use Catalyst 4000 series code base Catalyst 2901, 2902, 2926[T,F,GS,GL], 2948 - use Catalyst 5000 series code base 8.xGLX (The earlier 8.xGLX than Cisco CatOS 8.3(2)GLX) 8.x (The earlier than Cisco CatOS 8.2(2)) 7.x (The earlier than Cisco CatOS 7.6(6)) 6.x (The earlier than Cisco CatOS 6.4(9)) 5.x and earlier (The earlier than Cisco CatOS 5.5(20)) |
ÇØ°áÃ¥ |
´ÙÀ½ Cisco º¸¾È ±Ç°í¾È(Cisco CatOS Telnet, HTTP and SSH Vulnerability)ÀÇ "Software Versions and Fixes" ¸¦ ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml
¾÷±×·¹À̵åµéÀº Cisco À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.
ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼ º¼ ¼ö ÀÖ´Ù: http://www.cisco.com/warp/public/707/cisco-sa-20040609-catos.shtml |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
10504 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|