English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12088
À§Çèµµ 30
Æ÷Æ®
ÇÁ·ÎÅäÄÝ SCTP
ºÐ·ù Protocol
»ó¼¼¼³¸í ÇØ´ç ¸®´ª½º È£½ºÆ®´Â ¿¹±âÄ¡ ¸øÇÑ ECNE Chunk µ¥ÀÌÅ͸¦ °¡Áø SCTP ÆÐŶÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¸®´ª½º Ä¿³Î ½ºÆ®¸² Á¦¾î Àü¼Û ÇÁ·ÎÅäÄÝ(lksctp) ÇÁ·ÎÁ§Æ®´Â ¸®´ª½º Ä¿³Î »ó¿¡¼­ ½ºÆ®¸² Á¦¾î Àü¼Û ÇÁ·ÎÅäÄÝ(SCTP)À» ±¸ÇöÇÑ °ÍÀÌ´Ù. ¸®´ª½º Ä¿³Î 2.6.17 ÀÌÀüÀÇ 2.6.16.x ¹öÀüµé¿¡ ÀÖ´Â SCTP ±¸ÇöÀº CLOSED state ´Ü°è¿¡¼­ ¼ö½ÅµÈ ECNE Chunk µ¥ÀÌÅÍ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚ°¡ ¼­ºñ½º °ÅºÎ °ø°ÝÀ» ÀÏÀ¸Å³ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ä¿³Î PanicÀ» À¯¹ßÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://lksctp.sourceforge.net/
http://www.networksorcery.com/enp/protocol/sctp.htm#Chunk
http://git.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=35d63edb1c807bc5317e49592260e84637bc432e

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Kernel.Org Organization »ç, Linux kernel 2.6.17 ÀÌÀüÀÇ 2.6.16.x ¹öÀüµé
ÇØ°áÃ¥ Linux kernelÀÇ °¡Àå ÃÖ½ÅÀÇ stable ¹öÀü(2.6.17 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ¾÷±×·¹À̵å Á¤º¸´Â ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿©¾ß ÇÑ´Ù. Linux kernelÀÇ °ø½Ä À¥ »çÀÌÆ®´Â http://www.kernel.org/ ¿¡ ÀÖ´Â "Linux Kernel Archives" ÀÌ´Ù.

-- ȤÀº --

´ÙÀ½ Red Hat Linux Security Advisory RHSA-2006:0493-6¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵带 Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
https://rhn.redhat.com/errata/RHSA-2006-0493.html
°ü·Ã URL CVE-2006-2271 (CVE)
°ü·Ã URL 17910 (SecurityFocus)
°ü·Ã URL 26430 (ISS)