English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14152
À§Çèµµ 40
Æ÷Æ® 23
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù TELNET
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®ÀÇ ¸®´ª½º Ä¿³Î Á¤º¸¿¡ ÀÇÇÏ¸é ´ª½º Ä¿³ÎÀÇ ÀåÄ¡Á¦¾î API ó¸® °úÁ¤¿¡¼­ ¼­ºñ½º °ÅºÎ°¡ °¡´ÉÇÑ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ °ø°ÝÀÚ´Â Ãë¾àÇÑ ¸®´ª½º ¼­¹ö¿¡ Á¶ÀÛµÈ TCP ÆÐŶÀ» Àü¼ÛÇÏ¿© ¼­ºñ½º°¡ ¼­¼­È÷ Áö¿¬µÇ¾î ¸¶ºñµÇ´Â ¿î¿µ Àå¾Ö¸¦ ¹ß»ý½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.kernel.org/
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö TELNET ¼­¹öÀÇ kernel Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Kernel 4.15 ÀÌÀü 4.x ¹öÀüµé
ÇØ°áÃ¥ - ¸®´ª½º Ä¿³ÎÀ» Á÷Á¢ ¼³Ä¡ÇÏ¿© »ç¿ëÇÏ´Â ¼­¹öÀÇ °æ¿ì
´ÙÀ½ °øÁö¸¦ Âü°íÇÏ¿© ÃֽŠ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë
https://www.kernel.org/

- Redhat
´ÙÀ½ °øÁö¸¦ Âü°íÇÏ¿© ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë
https://access.redhat.com/security/cve/cve-2019-11477
https://access.redhat.com/security/cve/cve-2019-11478
https://access.redhat.com/security/cve/cve-2019-11479

- CentOS
´ÙÀ½ °øÁö¸¦ Âü°íÇÏ¿© ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë
https://lists.centos.org/pipermail/centos-announce/2019-June/023332.html
https://lists.centos.org/pipermail/centos-announce/2019-June/023333.html

- Ubuntu :
´ÙÀ½ °øÁö¸¦ Âü°íÇÏ¿© ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë
https://usn.ubuntu.com/
https://usn.ubuntu.com/4017-1/
https://usn.ubuntu.com/4017-2/
°ü·Ã URL CVE-2019-11477,CVE-2019-11478,CVE-2019-11479 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)