English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14021
À§Çèµµ 30
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Ssh
»ó¼¼¼³¸í ÇØ´ç SSH µ¥¸óÀÇ ¹öÀüÀÌ 1.2.27 ÀÌÇÏÀÌ´Ù.
Kerberos ÀÎÁõü°è¸¦ °®Ãá SSH 1.2.27 ÀÌÇÏ ¹öÀüÀº ·Î±×ÀÎÇÑ »ç¿ëÀÚÀÇ È¨µð·ºÅ丮¿¡ Kerberos ƼÄÏÀ» ÀϽÃÀûÀ¸·Î ÀúÀåÇÏ´Â ÆÄÀÏÀ» »ý¼ºÇÏ´Â °áÇÔÀÌ ÀÖ´Ù. ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© »ç¿ëÀÚ È¨µð·ºÅ丮¿¡ Àִ ƼÄÏ ÆÄÀÏÀÌ NFS(³×Æ®¿öÅ© ÆÄÀϰøÀ¯ ¼­ºñ½º)¸¦ ÅëÇØ ¿ÜºÎ Attacker¿¡°Ô º¸¿©Áø´Ù¸é Kerberos ƼÄÏÀÌ À¯ÃâµÇ¾î Kerberos ÀÎÁõü°è°¡ À§Çù¹ÞÀ» ¼ö ÀÖ´Ù.

* ¸¸¾à Kerberos¸¦ ÀÌ¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀÌ Ãë¾àÁ¡Àº ¹«½ÃÇÏ¿©µµ µÊ

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/1426
http://www.iss.net/security_center/static/4903.php
ÇØ°áÃ¥ 1.2.32 ¹öÀüÀ̳ª ±×ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù.
(SSH 1.2.28 ÀÌ»óÀÇ ¹öÀü¿¡¼­´Â ÀÌ·¯ÇÑ ¹®Á¦Á¡ÀÌ ¾ø´Ù. ÇÏÁö¸¸ 1.2.32 ÀÌÀüÀÇ ¹öÀüµéÀº ¸î°¡Áö ½É°¢ÇÑ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.)
°ü·Ã URL CVE-2000-0575 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)