| Ãë¾àÁ¡ID |
17013 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
1024 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
¸î¸î Linux ¹èÆ÷ ¹öÀüµé¿¡ ÀÖ´Â NFS (Network File System) lock µ¥¸óÀº ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¼öÇàÁßÀÎ rpc.lockd Æ÷Æ® (ÀϹÝÀûÀ¸·Î 1024 Æ÷Æ®)¿¡ Á¢¼ÓÇÏ¿© ÀÓÀÇÀÇ ÀÔ·Â µ¥ÀÌŸ¸¦ °ø±ÞÇÔÀ¸·Î½á ±× ¼ºñ½º¸¦ ¸ØÃç¹ö¸®°Ô ÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Debian 2.1 ~ 2.2 Linux Red Hat 6.0 ~ 6.2 Linux Mandrake 6.0 ~ 6.1, 7.0 ~ 7.1
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/5050.php http://www.securityfocus.com/archive/1/64258 |
| ÇØ°áÃ¥ |
½Ã½ºÅÛÀ» NFS Ŭ¶óÀÌ¾ðÆ®³ª ¼¹ö·Î »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀÌ ¼ºñ½º¸¦ ÁßÁö½ÃÄÑ¾ß ÇÑ´Ù. rpc.lockd´Â Á¤»óÀûÀÏ °æ¿ì 1024 Æ÷Æ®¸¦ »ç¿ëÇϱ⠶§¹®¿¡ ipfw¸¦ ÀÌ¿ëÇÏ¿© ÀÌ ¼ºñ½º¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Â÷´ÜÇÒ ¼öµµ ÀÖ´Ù. ¹Ýµå½Ã »ç¿ëÇÏ¿©¾ß ÇÑ´Ù¸é º¸¾È¿¡ ¹®Á¦°¡ ¾ø´ÂÁö ÇØ´ç Vendor¿¡ ¹®ÀÇ ÈÄ »ç¿ëÇÑ´Ù.
* °¡µ¿ÁßÁö ¹æ¹ý
1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/inetd.conf ÆÄÀÏ¿¡¼ 'nlockmgr' ¶óÀÎ (rpc.lockd) À» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]). |
| °ü·Ã URL |
CVE-2000-0508 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|