English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14013
À§Çèµµ 20
Æ÷Æ® 512
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù R-Command
»ó¼¼¼³¸í rexecd ¼­ºñ½º°¡ OpenµÇ¾î ÀÖ´Ù. rexecd´Â ¼­ºñ½ºÀÇ Á߿䵵¿¡ ºñÇØ ÀÎÁõ¼ö´ÜÀÌ ³Ê¹« ½±°Ô ¹«·ÂÈ­µÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ¼­¹ö°£ R-commandÀÇ Trust °ü°è¸¦ »çÀü¿¡ ¾Ë¾Æ³»¾î IP spoofingµîÀ» ÀÌ¿ë, ¼­¹öÀÇ ÀÎÁõÀ» ¼Ó¿© Target¼­¹öÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/675.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ °¡´ÉÇÑÇÑ ¼­ºñ½º¸¦ °¡µ¿Áß´Ü ÇÑ´Ù. ¼­ºñ½º¸¦ °¡µ¿Áß´Ü Çϱâ À§Çؼ­´Â /etc/inetd.conf¿¡¼­ rexec ¶óÀÎÀ» comment ó¸®Çϰí inetd µ¥¸óÀ» Restart ½ÃŲ´Ù.

Enterprise Linux 6.4, CentOS 6.4, Fedora 19ÀÇ °æ¿ì /etc/xinetd.d/rexec ÆÄÀÏÀ» ¿­¾î disableÀ» yes·Î º¯°æÇÑ ÈÄ inetd µ¥¸óÀ» Restart ½ÃŲ´Ù.

Solaris 10, Solaris 11 ÀÇ °æ¿ì ´ÙÀ½°ú °°ÀÌ ¼­ºñ½º¸¦ ÁßÁö½Ãų ¼ö ÀÖ´Ù.
# svcadm disable svc:/network/rexec:default
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)