English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14004
À§Çèµµ 40
Æ÷Æ® 23
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù TELNET
»ó¼¼¼³¸í ÇØ´ç telnet µ¥¸óÀº Format String °ø°Ý¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù.
Silicon Graphics (SGI)»çÀÇ Irix 6.2 ¿¡¼­ 6.5.8 »çÀÌÀÇ ¹öÀüµé¿¡ ÀÖ´Â Telnet µ¥¸ó°ú Irix 5.2 ¿¡¼­ 6.1 »çÀÌÀÇ ÆÐÄ¡µÈ telnet µ¥¸óÀÇ ¹öÀüµé¿¡´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Telnetd´Â »ç¿ëÀÚ¿¡ ÀÇÇØ Àü´ÞµÈ µ¥ÀÌÅ͸¦ ¿©°ú¾øÀÌ »ç¿ëÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÌ µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù. Telnet µ¥¸óÀÇ °æ¿ì root ±ÇÇÑÀ¸·Î ¼öÇàµÈ´Ù.
Telnet µ¥¸óÀº _RLD ȯ°æº¯¼öµé ÁßÀÇ Çϳª¸¦ ¼ÂÇϱâ À§ÇØ IAB-SB-TELOPT_ENVIRON ¿äûÀ» ÅëÇØ ÇϳªÀÇ ¿äûÀ» ¹Þ°ÔµÇ¸é syslog()·Î ÀÌ ½Ãµµ¸¦ ·Î±ëÇÑ´Ù. Á¤»óÀûÀ¸·Î´Â ȯ°æº¯¼ö¸í°ú ȯ°æº¯¼öÀÇ °ª µ¥ÀÌÅͰ¡ ·Î±ëµÈ´Ù. ¹®Á¦´Â Syslog¸¦ È£ÃâÇÒ ¶§ Format StringÀ» Æ÷ÇÔÇÑ º¯¼öµé°¡ Á¦°øµÉ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù. ÀÌ º¯¼öµéÀÇ ³»¿ëÀ» ÀûÀýÇÏ°Ô Á¶ÀÛÇÔÀ¸·Î½á Á¦°øµÈ Äڵ尡 root ±ÇÇÑÀ¸·Î ½ÇÇàµÉ ¼ö ÀÖµµ·Ï ½ºÅÿ¡ °ªµéÀ» µ¤¾î¾µ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/1572
http://www.cert.org/advisories/CA-1995-14.html
ÇØ°áÃ¥ ÅÚ³Ý ¼­ºñ½º°¡ ºÒÇÊ¿äÇÑ °æ¿ì ÅÚ³Ý ´ë¸óÀ» °¡µ¿ ÁßÁö½Ã۰í ssh ¿Í °°Àº º¸¾È ±â´ÉÀ» °¡Áø ´Ù¸¥ ¼­ºñ½º·Î ´ëÃ¼ÇØ¾ß ÇÑ´Ù.

* ÅÚ³Ý ¼­ºñ½º ÁßÁö ¹æ¹ý :

1. ½Ã½ºÅÛ¿¡ ·çÆ® ±ÇÇÑÀ» °®´Â´Ù.
% su
Password:
#
2. /etc/inetd.conf (IRIX 5.3 ÀÌÇÏÀÇ °æ¿ì, /usr/etc/inetd.conf) ÆÄÀÏ¿¡¼­ Åڳݵ¥¸ó ¼­ºñ½º¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù.
# vi /etc/inetd.conf
telnet stream tcp nowait root /usr/etc/telnetd telnetd
=> #telnet stream tcp nowait root /usr/etc/telnetd telnetd
3. inetd ´ë¸óÀÇ ¼³Á¤ ÆÄÀÏÀ» °­Á¦·Î ´Ù½Ã ÀÐ¾î µéÀδÙ.
# /etc/killall -HUP inetd
4. ÇöÀç ½ÇÇà ÁßÀÎ ÅÚ³Ý ´ë¸óÀ» Á¾·á½ÃŲ´Ù.
# /etc/killall telnetd
5. ·çÆ® ±ÇÇÑÀ» ¹þ¾î³­´Ù.
# exit
%

-- ¶Ç´Â --

ÅÚ³Ý ¼­ºñ½º°¡ ÇÊ¿äÇÑ °æ¿ì Áï½Ã ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. ÆÐÄ¡¸¦ À§Çؼ­´Â ´ÙÀ½ »çÀÌÆ®µéÀ» ÂüÁ¶ÇÑ´Ù.

* IRIX 5.2-6.4 :

http://support.sgi.com/irix/ and ftp://patches.sgi.com/support/patchset/

* IRIX 6.5 Maintenance Release Streams :

http://support.sgi.com/colls/patches/tools/relstream/index.html
°ü·Ã URL CVE-2000-0733 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)