English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12040
À§Çèµµ 40
Æ÷Æ® 123
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù NTPD
»ó¼¼¼³¸í ¸¹Àº ¿î¿µÃ¼Á¦¿¡ Æ÷ÇÔµÈ Network Time Protocol Daemon (ntpd) 4.0.99k ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°Ý¿¡¼­ÀÇ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù. 'readvar' Àμö¸¦ ¾ÆÁÖ ¸¹ÀÌ ÁØ Query¿¡ ´ëÇÑ ÀÀ´äÀ» ¸¸µé¾î ³¾ ¶§ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÑ´Ù. À̸¦ ÀÌ¿ëÇÏ¸é °ÅÀÇ ´ëºÎºÐÀÇ °æ¿ì ntpd µ¥¸óÀº °ü¸®ÀÚ ±ÇÇÑÀ¸·Î ÀÛµ¿µÇ±â ¶§¹®¿¡ ¿ø°ÝÁöÀÇ timeserver¿¡ ´ëÇÑ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô µÈ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ¼­ºñ½ºÀÇ °¡µ¿À» ÁßÁöÇÏ¿©¾ß ÇÑ´Ù. ±×·¸Áö ¾ÊÀ¸¸é ¾÷±×·¹À̵å ÇÑ´Ù.

Debian 2.2 potato:
Debian º¸¾È ±Ç°í¾È DSA-045-1¿¡ ¸®½ºÆ®µÈ ´ë·Î ntpÀÇ ÃֽйöÀü (4.0.99g-2potato1 ÀÌ»ó) À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://www.mail-archive.com/debian-security@lists.debian.org/msg01806.html
http://lists.debian.org/debian-security-announce/2001/msg00043.html

NetBSD 1.4 ¿Í 1.5:
NetBSD º¸¾È ±Ç°í¾È 2001-004¿¡ ¸®½ºÆ®µÈ ´ë·Î ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù.
http://mail-index.netbsd.org/tech-security/2001/04/05/0000.html
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-004.txt.asc

´Ù¸¥ ¿î¿µÃ¼Á¦µé:
¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾ò±â À§ÇØ ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÑ´Ù.
°ü·Ã URL CVE-2001-0414 (CVE)
°ü·Ã URL 2540 (SecurityFocus)
°ü·Ã URL 6321 (ISS)