English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12033
À§Çèµµ 40
Æ÷Æ®
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç Linux rpc.statd/rpc.kstatd µ¥¸óÀº Format String °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Rpc.statd/rpc.kstatd´Â NFS file-locking Status MonitorÀÌ´Ù. RPC (Remote Procedure Call) statd´Â NFS (Network File System)À» ÅëÇØ file locking¿¡ ´ëÇÑ Crash¿Í Recovery ±â´ÉÀ» Á¦°øÇϱâ À§ÇØ RPC lockd¿Í ÇÔ²² »óÈ£ÀÛµ¿Çϸ鼭 »óÅ Á¤º¸¸¦ À¯Áö, °ü¸®ÇÑ´Ù.
ÀÌ ÇÁ·Î±×·¥ÀÇ ·Î±ë ½Ã½ºÅÛ¿¡ ÀÖ´Â °áÇÔÀ¸·Î ÀÎÇØ, ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ žÀçµÈ rpc.statd/rpc.kstatd ¼­¹ö´Â °ø°ÝÀÚ°¡ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ ÇÁ·Î±×·¥¿¡¼­´Â ¿ø°ÝÁöÀÇ »ç¿ëÀÚ·Î ºÎÅÍ ¾î¶² ÇÊÅ͸µ °úÁ¤¾øÀÌ Á÷Á¢ÀûÀ¸·Î ¹Þ¾Æ ¿Â µ¥ÀÌÅ͸¦ °¡Áö°í syslog()¸¦ È£ÃâÇÑ´Ù. ÀÌ µ¥ÀÌÅÍ´Â printf() ½ºÅ¸ÀÏÀÇ Format ¹®ÀÚ¿­µéÀ» Æ÷ÇÔÇÒ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ RPC ¸Þ½ÃÁö¸¦ Ãë¾àÇÑ ¼­¹ö·Î º¸³¿À¸·Î½á °ø°ÝÀÚ´Â root ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÇØ´ç rpc.statd µ¥¸óÀº Format String Å×½ºÆ®¿¡ ÀÇÇØ Å©·¡½¬°¡ ³¯ ¼ö ÀÖ´Ù. ÀÌ ¶§¹®¿¡ Á¤»óÀûÀÎ ±â´ÉÀ» ÇÏ°Ô Çϱâ À§Çؼ­´Â ÀÌ ¼­ºñ½º¸¦ Àç°¡µ¿½ÃÄÑ¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/1480
http://www.iss.net/security_center/static/4939.php

Ãë¾àÇÑ Ç÷§Æû:
Conectiva Linux: All Versions
Debian Linux 2.2
Debian Linux 2.3
Mandrake Linux 7.0
Mandrake Linux 7.1
Red Hat Linux 6.0
Red Hat Linux 6.1
Red Hat Linux 6.2
SuSE Linux 6.1
SuSE Linux 6.2
SuSE Linux 6.3
SuSE Linux 6.4
ÇØ°áÃ¥ ¸¸¾à ÇØ´ç È£½ºÆ®°¡ NFS Ŭ¶óÀÌ¾ðÆ®³ª ¼­¹ö·Î ÀÛµ¿ÇÏÁö ¾Ê´Â´Ù¸é 'rpc.statd' rpc ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö½ÃÄÑ¾ß ÇÑ´Ù.

-- ȤÀº --

¿î¿µÃ¼Á¦¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.

Linux-MandrakeÀÇ °æ¿ì:
Vender¿¡°Ô ¹®ÀÇÇÏ¿© nfs-utilsÀÇ ÃֽйöÀü (0.1.9.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Red Hat LinuxÀÇ °æ¿ì:
Vender¿¡°Ô ¹®ÀÇÇÏ¿© nfs-utilsÀÇ ÃֽйöÀü (0.1.9.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Conectiva LinuxÀÇ °æ¿ì:
Conectiva Linux º¸¾È ±Ç°í¾È CLSA-2000:250, Áï Vender¿¡°Ô ¹®ÀÇÇÏ¿© nfs-utilsÀÇ ÃֽйöÀü (0.1.9.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian LinuxÀÇ °æ¿ì:
Debian Linux º¸¾È ±Ç°í¾È 20000719a, Áï http://www.debian.org/security/2000/20000719a ¿¡ ³ª¿Í ÀÖµíÀÌ nfs-utilsÀÇ ÃֽйöÀü (0.1.9.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Trustix LinuxÀÇ °æ¿ì:
Vender¿¡°Ô ¹®ÀÇÇÏ¿© nfs-utilsÀÇ ÃֽйöÀü (0.1.9.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

±âŸÀÇ °æ¿ì:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¿¡ ´ëÇØ ¹®ÀÇÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2000-0666 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)