English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12084
À§Çèµµ 40
Æ÷Æ® 389
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LDAP
»ó¼¼¼³¸í ÇØ´ç CommuniGate Pro LDAP ¼­ºñ½º´Â 5.0.7 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. CommuniGate Pro´Â »ó¿ë e-mail ¹× groupware ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. CommuniGate Pro Core ¼­¹ö ¹öÀü 5.0.6À» Æ÷ÇÔÇÑ ±× ÀÌÀüÀÇ ¹öÀüµéÀº BER(Basic Encoding Rules) 'length' Çʵåµé¿¡ À½¼ö ±æÀÌ °ªµéÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼­ÀÇ LDAP ±¸¼º¿ä¼Ò¿¡ ÀÖ´Â ¿À·ùµé·Î ÀÎÇÏ¿©, ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Å³ª ½ÉÁö¾î ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ProtoVer LDAP Å×½ºÆ® ½´Æ®(suite)¸¦ ÅëÇØ ¹ß°ßµÇ¾ú´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/423364
http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041863.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0923.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0974.html
http://secunia.com/advisories/18640/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Stalker Software »ç, CommuniGate Pro ¹öÀü 5.0.6À» Æ÷ÇÔÇÑ ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ CommuniGate Pro À¥ ÆäÀÌÁöÀÎ http://www.stalker.com/CommuniGatePro/default.html ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â CommuniGate Pro ServerÀÇ °¡Àå ÃֽŠ¹öÀü(5.0.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-0468 (CVE)
°ü·Ã URL 16407 (SecurityFocus)
°ü·Ã URL 24409 (ISS)