| Ãë¾àÁ¡ID |
14004 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
23 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
TELNET |
| »ó¼¼¼³¸í |
ÇØ´ç telnet µ¥¸óÀº Format String °ø°Ý¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³´Ù. Silicon Graphics (SGI)»çÀÇ Irix 6.2 ¿¡¼ 6.5.8 »çÀÌÀÇ ¹öÀüµé¿¡ ÀÖ´Â Telnet µ¥¸ó°ú Irix 5.2 ¿¡¼ 6.1 »çÀÌÀÇ ÆÐÄ¡µÈ telnet µ¥¸óÀÇ ¹öÀüµé¿¡´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Telnetd´Â »ç¿ëÀÚ¿¡ ÀÇÇØ Àü´ÞµÈ µ¥ÀÌÅ͸¦ ¿©°ú¾øÀÌ »ç¿ëÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÌ µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù. Telnet µ¥¸óÀÇ °æ¿ì root ±ÇÇÑÀ¸·Î ¼öÇàµÈ´Ù. Telnet µ¥¸óÀº _RLD ȯ°æº¯¼öµé ÁßÀÇ Çϳª¸¦ ¼ÂÇϱâ À§ÇØ IAB-SB-TELOPT_ENVIRON ¿äûÀ» ÅëÇØ ÇϳªÀÇ ¿äûÀ» ¹Þ°ÔµÇ¸é syslog()·Î ÀÌ ½Ãµµ¸¦ ·Î±ëÇÑ´Ù. Á¤»óÀûÀ¸·Î´Â ȯ°æº¯¼ö¸í°ú ȯ°æº¯¼öÀÇ °ª µ¥ÀÌÅͰ¡ ·Î±ëµÈ´Ù. ¹®Á¦´Â Syslog¸¦ È£ÃâÇÒ ¶§ Format StringÀ» Æ÷ÇÔÇÑ º¯¼öµé°¡ Á¦°øµÉ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù. ÀÌ º¯¼öµéÀÇ ³»¿ëÀ» ÀûÀýÇÏ°Ô Á¶ÀÛÇÔÀ¸·Î½á Á¦°øµÈ Äڵ尡 root ±ÇÇÑÀ¸·Î ½ÇÇàµÉ ¼ö ÀÖµµ·Ï ½ºÅÿ¡ °ªµéÀ» µ¤¾î¾µ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/1572 http://www.cert.org/advisories/CA-1995-14.html |
| ÇØ°áÃ¥ |
ÅÚ³Ý ¼ºñ½º°¡ ºÒÇÊ¿äÇÑ °æ¿ì ÅÚ³Ý ´ë¸óÀ» °¡µ¿ ÁßÁö½Ã۰í ssh ¿Í °°Àº º¸¾È ±â´ÉÀ» °¡Áø ´Ù¸¥ ¼ºñ½º·Î ´ëÃ¼ÇØ¾ß ÇÑ´Ù.
* ÅÚ³Ý ¼ºñ½º ÁßÁö ¹æ¹ý :
1. ½Ã½ºÅÛ¿¡ ·çÆ® ±ÇÇÑÀ» °®´Â´Ù. % su Password: # 2. /etc/inetd.conf (IRIX 5.3 ÀÌÇÏÀÇ °æ¿ì, /usr/etc/inetd.conf) ÆÄÀÏ¿¡¼ Åڳݵ¥¸ó ¼ºñ½º¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù. # vi /etc/inetd.conf telnet stream tcp nowait root /usr/etc/telnetd telnetd => #telnet stream tcp nowait root /usr/etc/telnetd telnetd 3. inetd ´ë¸óÀÇ ¼³Á¤ ÆÄÀÏÀ» °Á¦·Î ´Ù½Ã ÀÐ¾î µéÀδÙ. # /etc/killall -HUP inetd 4. ÇöÀç ½ÇÇà ÁßÀÎ ÅÚ³Ý ´ë¸óÀ» Á¾·á½ÃŲ´Ù. # /etc/killall telnetd 5. ·çÆ® ±ÇÇÑÀ» ¹þ¾î³´Ù. # exit %
-- ¶Ç´Â --
ÅÚ³Ý ¼ºñ½º°¡ ÇÊ¿äÇÑ °æ¿ì Áï½Ã ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. ÆÐÄ¡¸¦ À§Çؼ´Â ´ÙÀ½ »çÀÌÆ®µéÀ» ÂüÁ¶ÇÑ´Ù.
* IRIX 5.2-6.4 :
http://support.sgi.com/irix/ and ftp://patches.sgi.com/support/patchset/
* IRIX 6.5 Maintenance Release Streams :
http://support.sgi.com/colls/patches/tools/relstream/index.html |
| °ü·Ã URL |
CVE-2000-0733 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|