English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17040
À§Çèµµ 40
Æ÷Æ® 32785/32786
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í Sun Solaris ¹öÀü 2.6, 7°ú 8¿¡¼­ÀÇ snmpXdmid ¼­ºñ½º DaemonÀº Buffer Overflow¿¡ Ãë¾àÇÏ´Ù. 'snmpXdmid' ¼­ºñ½º´Â SNMP¿Í DMI (Desktop Management Interface) Request¸¦ ó¸®Çϱâ À§ÇÑ ¸ÅÇÎ ÅøÀÌ´Ù.
snmpXdmid´Â SNMP Æ®·¦À¸·Î ¾ÇÀÇÀûÀÎ DMI request¸¦ Çؼ®ÇÒ ¶§ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÑ´Ù. SnmpXdmind´Â ·çÆ® ±ÇÇÑÀ¸·Î ½ÇÇàµÇ±â ¶§¹®¿¡ °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇؼ­ °ø°Ý¿¡ ¼º°øÇÏ¸é ½´ÆÛÀ¯ÀúÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Sun Solaris ¹öÀü 2.6, 7°ú 8
ÇØ°áÃ¥ Sun SolarisÀÇ °æ¿ì:
´ÙÀ½°ú °°ÀÌ ½Ã½ºÅÛ¿¡ ¸Â´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù. https://support.oracle.com¿¡¼­ ÇØ´ç ÆÐÄ¡¸¦ Áö¿øÇÏÁö ¾ÊÀ» °æ¿ì º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.

SunOS 5.8 108869-07
SunOS 5.8_x86 108870-07
SunOS 5.7 107709-15
SunOS 5.7_x86 107710-15
SunOS 5.6 106787-15
SunOS 5.6_x86 106872-15


-- ȤÀº --

¸¸¾à SNMP ±×¸®°í DMI°¡ ¸ðµÎ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é DMI¸¦ ³»·Á ³õÀ½À¸·Î½á 'snmpXdmid' ´ë¸óÀ» »ç¿ë ÁßÁö½Ãų ¼ö ÀÖ´Ù.

DMI¸¦ ¿ÏÀüÇÏ°Ô ³»·Á ³õ±â À§Çؼ­´Â:

1. /etc/rc?.d/S??dmi¸¦ /etc/rc?.d/K07dmi·Î À̸§À¸·Î ¹Ù²Ù¾î ³õ´Â´Ù. ±×¸®°í '/etc/init.d/init.dmi stop' (¿©±â¼­ÀÇ ?´Â ÀûÀýÇÑ runlevel À» ¶æÇÔ) À» ½ÇÇàÇÑ´Ù.

2. ¸¸¾à ´ë¸óÀÌ ½ÇÇàµÇÁö ¾Êµµ·Ï ¸¸µé°íÀÚ ÇÑ´Ù¸é 'snmpXdmid' ÀÌÁø ÆÄÀϷκÎÅÍ ¸ðµç Æ۹̼ǵéÀ» Á¦°ÅÇÑ´Ù:
# chmod 000 /usr/lib/dmi/snmpXdmid

3. snmpXdmid RPC ¼­¹ö½ºÀÇ ID´Â 100249¹øÀÌ´Ù. ·ÎÄà ȣ½ºÆ®ÀÇ Æ÷Æ® ¹ÙÀεù »óŸ¦ ¸®½ºÆ®ÇØ º¸±â À§Çؼ­´Â 'rpcinfo -p' ¸í·ÉÀ» »ç¿ëÇÑ´Ù:
# rpcinfo -p | grep 100249
100249 1 udp 32785
100249 1 tcp 32786

¸¸¾à ÇöÀç snmpXdmid RPC ¼­ºñ½º¸¦ »ç¿ë ÁßÁö½ÃÅ°±â À§Çؼ­´Â ´ÙÀ½ ¸í·ÉÀ» ¼öÇàÇÑ´Ù:
# rpcinfo -d 100249 ? (¿©±â¼­ÀÇ ?´Â snmpXdmid RPC ¼­ºñ½ºÀÇ ¹öÀüÀ» ¶æÇÑ´Ù. ¿©±â¿¡¼­ÀÇ °æ¿ì´Â '1'ÀÌ´Ù)
°ü·Ã URL CVE-2001-0236 (CVE)
°ü·Ã URL 2417 (SecurityFocus)
°ü·Ã URL 6245 (ISS)