| Ãë¾àÁ¡ID |
14013 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
512 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
R-Command |
| »ó¼¼¼³¸í |
rexecd ¼ºñ½º°¡ OpenµÇ¾î ÀÖ´Ù. rexecd´Â ¼ºñ½ºÀÇ Á߿䵵¿¡ ºñÇØ ÀÎÁõ¼ö´ÜÀÌ ³Ê¹« ½±°Ô ¹«·Â鵃 ¼ö ÀÖ´Ù. ¶ÇÇÑ ¼¹ö°£ R-commandÀÇ Trust °ü°è¸¦ »çÀü¿¡ ¾Ë¾Æ³»¾î IP spoofingµîÀ» ÀÌ¿ë, ¼¹öÀÇ ÀÎÁõÀ» ¼Ó¿© Target¼¹öÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/675.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
°¡´ÉÇÑÇÑ ¼ºñ½º¸¦ °¡µ¿Áß´Ü ÇÑ´Ù. ¼ºñ½º¸¦ °¡µ¿Áß´Ü Çϱâ À§Çؼ´Â /etc/inetd.conf¿¡¼ rexec ¶óÀÎÀ» comment ó¸®Çϰí inetd µ¥¸óÀ» Restart ½ÃŲ´Ù.
Enterprise Linux 6.4, CentOS 6.4, Fedora 19ÀÇ °æ¿ì /etc/xinetd.d/rexec ÆÄÀÏÀ» ¿¾î disableÀ» yes·Î º¯°æÇÑ ÈÄ inetd µ¥¸óÀ» Restart ½ÃŲ´Ù.
Solaris 10, Solaris 11 ÀÇ °æ¿ì ´ÙÀ½°ú °°ÀÌ ¼ºñ½º¸¦ ÁßÁö½Ãų ¼ö ÀÖ´Ù. # svcadm disable svc:/network/rexec:default |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|