Ãë¾àÁ¡ID |
17040 |
À§Çèµµ |
40 |
Æ÷Æ® |
32785/32786 |
ÇÁ·ÎÅäÄÝ |
TCP,UDP |
ºÐ·ù |
RPC |
»ó¼¼¼³¸í |
Sun Solaris ¹öÀü 2.6, 7°ú 8¿¡¼ÀÇ snmpXdmid ¼ºñ½º DaemonÀº Buffer Overflow¿¡ Ãë¾àÇÏ´Ù. 'snmpXdmid' ¼ºñ½º´Â SNMP¿Í DMI (Desktop Management Interface) Request¸¦ ó¸®Çϱâ À§ÇÑ ¸ÅÇÎ ÅøÀÌ´Ù. snmpXdmid´Â SNMP Æ®·¦À¸·Î ¾ÇÀÇÀûÀÎ DMI request¸¦ Çؼ®ÇÒ ¶§ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÑ´Ù. SnmpXdmind´Â ·çÆ® ±ÇÇÑÀ¸·Î ½ÇÇàµÇ±â ¶§¹®¿¡ °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇؼ °ø°Ý¿¡ ¼º°øÇÏ¸é ½´ÆÛÀ¯ÀúÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sun Solaris ¹öÀü 2.6, 7°ú 8 |
ÇØ°áÃ¥ |
Sun SolarisÀÇ °æ¿ì: ´ÙÀ½°ú °°ÀÌ ½Ã½ºÅÛ¿¡ ¸Â´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù. https://support.oracle.com¿¡¼ ÇØ´ç ÆÐÄ¡¸¦ Áö¿øÇÏÁö ¾ÊÀ» °æ¿ì º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.
SunOS 5.8 108869-07 SunOS 5.8_x86 108870-07 SunOS 5.7 107709-15 SunOS 5.7_x86 107710-15 SunOS 5.6 106787-15 SunOS 5.6_x86 106872-15
-- ȤÀº --
¸¸¾à SNMP ±×¸®°í DMI°¡ ¸ðµÎ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é DMI¸¦ ³»·Á ³õÀ½À¸·Î½á 'snmpXdmid' ´ë¸óÀ» »ç¿ë ÁßÁö½Ãų ¼ö ÀÖ´Ù.
DMI¸¦ ¿ÏÀüÇÏ°Ô ³»·Á ³õ±â À§Çؼ´Â:
1. /etc/rc?.d/S??dmi¸¦ /etc/rc?.d/K07dmi·Î À̸§À¸·Î ¹Ù²Ù¾î ³õ´Â´Ù. ±×¸®°í '/etc/init.d/init.dmi stop' (¿©±â¼ÀÇ ?´Â ÀûÀýÇÑ runlevel À» ¶æÇÔ) À» ½ÇÇàÇÑ´Ù.
2. ¸¸¾à ´ë¸óÀÌ ½ÇÇàµÇÁö ¾Êµµ·Ï ¸¸µé°íÀÚ ÇÑ´Ù¸é 'snmpXdmid' ÀÌÁø ÆÄÀϷκÎÅÍ ¸ðµç Æ۹̼ǵéÀ» Á¦°ÅÇÑ´Ù: # chmod 000 /usr/lib/dmi/snmpXdmid
3. snmpXdmid RPC ¼¹ö½ºÀÇ ID´Â 100249¹øÀÌ´Ù. ·ÎÄà ȣ½ºÆ®ÀÇ Æ÷Æ® ¹ÙÀεù »óŸ¦ ¸®½ºÆ®ÇØ º¸±â À§Çؼ´Â 'rpcinfo -p' ¸í·ÉÀ» »ç¿ëÇÑ´Ù: # rpcinfo -p | grep 100249 100249 1 udp 32785 100249 1 tcp 32786
¸¸¾à ÇöÀç snmpXdmid RPC ¼ºñ½º¸¦ »ç¿ë ÁßÁö½ÃÅ°±â À§Çؼ´Â ´ÙÀ½ ¸í·ÉÀ» ¼öÇàÇÑ´Ù: # rpcinfo -d 100249 ? (¿©±â¼ÀÇ ?´Â snmpXdmid RPC ¼ºñ½ºÀÇ ¹öÀüÀ» ¶æÇÑ´Ù. ¿©±â¿¡¼ÀÇ °æ¿ì´Â '1'ÀÌ´Ù) |
°ü·Ã URL |
CVE-2001-0236 (CVE) |
°ü·Ã URL |
2417 (SecurityFocus) |
°ü·Ã URL |
6245 (ISS) |
|