English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12094
À§Çèµµ 30
Æ÷Æ® 389
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LDAP
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®´Â OpenLDAPÀ» °¡µ¿ Áß¿¡ ÀÖ´Â °ÍÀ¸·Î º¸À̸ç, ÀÌ ¼­¹ö´Â LDAP BIND ¿äûµéÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. OpenLDAPÀº ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ø°³ ¼Ò½º LDAP µð·ºÅ丮 ±¸ÇöÀÌ´Ù. OpenLDAP 2.3.29 ÀÌÀüÀÇ ¹öÀüµéÀº BIND ¿äûµéÀ» ó¸®ÇÒ ¶§ÀÇ ¿À·ù·Î ÀÎÇÏ¿©, ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ Àΰ¡¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â ±ä authcid À̸§µéÀ» °¡Áø Àß Á¶ÀÛµÈ BIND ¿äûÀ» º¸³¿À¸·Î½á ¼­¹ö¸¦ Å©·¡½¬½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/450728/30/0/threaded
http://secunia.com/advisories/22750/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenLDAP 2.3.29 ÀÌÀüÀÇ ¹öÀüµé
Linux Any version
ÇØ°áÃ¥ OpenLDAP ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://www.openldap.org/software/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â OpenLDAPÀÇ °¡Àå ÃֽŠ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Mandriva LinuxÀÇ °æ¿ì:
´ÙÀ½ Mandriva Linux Security Advisory MDKSA-2006:208À» ÂüÁ¶ÇÏ¿© openldapÀÇ ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/security/advisories?name=MDKSA-2006:208

Ubuntu LinuxÀÇ °æ¿ì:
´ÙÀ½ Ubuntu Security Notice USN-384-1À» ÂüÁ¶ÇÏ¿© openldapÀÇ ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.ubuntu.com/usn/usn-384-1

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Announcement GLSA 200611-25¸¦ ÂüÁ¶ÇÏ¿© OpenLDAPÀÇ ±³Á¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200611-25.xml
°ü·Ã URL CVE-2006-5779 (CVE)
°ü·Ã URL 20939 (SecurityFocus)
°ü·Ã URL 30076 (ISS)