| Ãë¾àÁ¡ID |
17005 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
111 |
| ÇÁ·ÎÅäÄÝ |
TCP,UDP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡ walld RPC ¼¹ö½º°¡ °¡µ¿µÇ°í ÀÖ´Ù. ÀÌ ¼ºñ½º´Â ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ³×Æ®¿öÅ©ÀÇ »ç¿ëÀڵ鿡°Ô ¾î¶² ¸Þ¼¼Áö¸¦ »ç¿ëÀÚ È¸é¿¡ ³ªÅ¸³ª°Ô Çϱâ À§ÇØ »ç¿ëµÈ´Ù. ±×·¯³ª ÀÌ ¼ºñ½º´Â ¾î¶² ÀÎÁõÀýÂ÷µµ °ÅÄ¡Áö ¾Ê±â ¶§¹®¿¡ ¾ÇÀÇÀÇ »ç¿ëÀÚ°¡ °ü¸®ÀÚ¿¡ ÀÇÇØ º¸³»Áø °ÍÀ¸·Î Á¶ÀÛÇÑ ¸Þ¼¼Áö¸¦ º¸³¿À¸·Î½á ÀÏ¹Ý »ç¿ëÀÚ¸¦ ¼ÓÀÏ ¼ö ÀÖ´Â ÇÔÁ¤À» ÁÙ ¼öµµ ÀÖ´Ù. ¶ÇÇÑ »ç¿ëÀÚ È¸é¿¡ ²÷ÀÓ¾øÀÌ ¾²·¹±â ¸Þ½ÃÁö¸¦ º¸³¿À¸·Î½á ÀÏ¹Ý »ç¿ëÀÚÀÇ Á¤»óÀûÀÎ ÀÛ¾÷À» ¹æÇØÇÏ¿© ¼ºñ½º °ÅºÎ°ø°ÝÀ¸·Î »ç¿ëµÉ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/150.php http://www.ciac.org/ciac/bulletins/ciac-05.shtml http://ciac.llnl.gov/ciac/bulletins/ciac-06.shtml
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀáÀçÀûÀÎ º¸¾È Ãë¾àÁ¡ÀÌ ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ÇØ´ç ¼ºñ½ºÀÇ °¡µ¿À» ÁßÁöÇÑ´Ù.
* °¡µ¿ÁßÁö ¹æ¹ý
1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/inetd.conf ÆÄÀÏ¿¡¼ 'walld' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]).
Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19 ÀÇ °æ¿ì: 1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/rpc ÆÄÀÏ¿¡¼ 'walld' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. # pkill -HUP (x)inetd |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|