| Ãë¾àÁ¡ID |
17007 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
111 |
| ÇÁ·ÎÅäÄÝ |
TCP,UDP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹öÀÇ NFS¿¡¼ Export ½ÃÄѳõÀº µð·ºÅ丮°¡ EveryoneÀ¸·Î exportµÇ¾î ÀÖ¾î ¾î¶² ¼¹ö¿¡¼µçÁö mountÇÏ¿© ±× µð·ºÅ丮¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. °æ¿ì¿¡ µû¶ó¼ À§ÇèÇÑ µð·ºÅ丮(½Ã½ºÅÛ µð·ºÅ丮³ª User Home µð·ºÅ丮)°¡ ³ëÃâµÇ¾î ÀÖ´Ù¸é ¿©·¯°¡Áö ¹æ¹ýÀ» µ¿¿øÇÏ¿© ¼¹ö¿¡ ħÅõÇÒ ¼ö ÀÖ´Â °æ·Î¸¦ ¸¸µé¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/74.php http://www.cert.org/advisories/CA-1991-21.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
/etc/exports ÆÄÀÏÀÌ NFSÀÇ export µð·ºÅ丮¿¡ ´ëÇÑ ¸ðµç ¼³Á¤ ³»¿ëÀÌ µé¾î ÀÖ´Â ÆÄÀÏÀÌ´Ù. ÀÌ ¶óÀÎ Áß µð·ºÅ丮¸í¸¸ Ç¥½ÃµÇ¾î ÀÖ´Â ºÎºÐÀÌ ÀÖ´Ù¸é ±× µð·ºÅ丮´Â ¿ÜºÎ¿¡¼ everyone mountableÇÑ µð·ºÅ丮°¡ µÈ´Ù. µû¶ó¼ ´ÙÀ½°ú °°ÀÌ Mount ÇÒ ¼ö ÀÖ´Â ¼¹ö¸¦ ¸í½ÃÀûÀ¸·Î ÁöÁ¤Çϰí ÀÌ¿ÍÇÔ²² Read¸¸ °¡´ÉÇÏ°Ô ÇÒ °ÍÀÎÁö ¾Æ´Ï¸é Update, Writeµµ °¡´ÉÇÏ°Ô ÇÒ °ÍÀÎÁö¿¡ ´ëÇÑ ¿É¼Çµµ ÇÔ²² Ç¥½ÃÇØ Áà¾ß ÇÑ´Ù.
/data/export-dir -ro=client.mydomain.co.kr |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|