English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14023
À§Çèµµ 40
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Ssh
»ó¼¼¼³¸í ÇØ´ç SSH ¼­¹öÀÇ ¹öÀüÀº 1.2.23 ÀÌÇÏÀÇ ¹öÀüÀÌ´Ù. ÇØ´ç SSH ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é °ø°ÝÀÚ´Â SSH ¼­¹ö¿¡¼­ ½ÇÇàµÉ ¼ö ÀÖ´Â ÀÓÀÇÀÇ ¸í·Éµé·Î º¹È£È­µÉ ½ºÆ®¸²¿¡ ¾ÏȣȭµÈ ºí·°À» »ðÀÔÇÒ ¼ö ÀÖ´Â "SSH insertion attack"·Î ¾Ë·ÁÁø Ãë¾àÁ¡ÀÌ ÀÖ´Ù. SSH (Secure Shell)Àº ³×Æ®¿öÅ© Åë½ÅÀÇ ÀÎÁõ°ú ¾Ïȣȭ¸¦ À§ÇÑ Å¬¶óÀ̾ðÆ®-¼­¹ö ÇÁ·Î±×·¥ÀÌ´Ù.
Ãë¾àÇÑ ¹öÀüµéÀÌ CBC (Cipher Block Chaining) ȤÀº CFB (Cipher Feedback 64 bits) ¸ðµåµé·Î »ç¿ëµÉ ¶§ °ø°ÝÀÚ´Â ¾Ë·ÁÁø plaintext °ø°Ý°ú ÆÐŶ¿¡ ´ëÇÑ Å¸´çÇÑ CRC-32 checksumÀ» °è»êÇÏ¿© SSH Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö°£¿¡ Á¸ÀçÇÏ´Â ½ºÆ®¸²À¸·Î ÀÓÀÇÀÇ µ¥ÀÌŸ¸¦ »ðÀÔÇÒ ¼ö ÀÖ´Ù. SSH ¹öÀü 1.2.23 ÀÌÇÏ¿Í F-Secure ¹öÀü 1.3.4 ÀÌÇÏÀÇ ¹öÀüµéÀÌ ÀÌ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÇöÀç ¼öÇàÁßÀÎ SSHÀÇ ¹öÀüÀ» È®ÀÎÇÏ°í ½ÍÀ¸¸é ÇØ´ç ½Ã½ºÅÛ »ó¿¡¼­ 'ssh -V'¸¦ ŸÀÌÇÎÇÏ¸é ¼³Ä¡µÈ SSHÀÇ ¹öÀüÀ» ¾Ë ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.corest.com/pressroom/advisories_desplegado.php?idxsection=10&idx=131#
http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525878&w=2
ÇØ°áÃ¥ http://www.openssh.com/¿¡¼­ SSHÀÇ ¹öÀü 1.2.25 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. F-Secure ¹öÀüÀÏ °æ¿ì F-Secure ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://www.f-secure.com/download-purchase/ À¸·Î ºÎÅÍ 1.3.5 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. Áö¿ø °è¾àÀ» ü°áÇÑ F-Secure »ç¿ëÀÚµéÀº ·ÎÄà ä³ÎÀ» ÅëÇØ ¾÷±×·¹À̵带 ¾òÀ» ¼ö ÀÖ´Ù.
°ü·Ã URL CVE-1999-1085 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)