English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17048
À§Çèµµ 20
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í RPC portmapper°¡ °¡µ¿µÇ°í ÀÖ´Ù. RPC ¼­ºñ½º´Â Buffer Overflow µîÀÇ °ø°Ý¿¡ ¸Å¿ì Ãë¾àÇÏ¿© ¸¹Àº ÇØÅ·¹æ¹ýµéÀÌ ½ñ¾ÆÁ® ³ª¿À°í ÀÖ´Ù.
ÀÌ ¼­ºñ½º´Â ÇöÀç ÇØ´ç ¼­¹ö¿¡ ¾î¶² RPC ¼­ºñ½º°¡ °¡µ¿µÇ°í ÀÖ´ÂÁö¿¡ ´ëÇÑ Á¤º¸¸¦ Ŭ¶óÀÌ¾ðÆ®¿¡°Ô ¾Ë·ÁÁØ´Ù. ÀÌ Á¤º¸´Â ÇØÄ¿¿¡°Ô ¸Å¿ì À¯¿ëÇÑ Á¤º¸°¡ µÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-1993-15.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ¿ÜºÎ¿¡¼­ ¼­ºñ½º¿¡ Á¢¼ÓÇÏÁö ¸øÇϵµ·Ï rpcbind °¡µ¿À» ÁßÁö½ÃÄÑ ³õ´Â´Ù.

1.´ÙÀ½ ¸í·ÉÀ¸·Î rpcbind¸¦ ÁßÁöÇÕ´Ï´Ù.
#rpcbind stop

2. ´ÙÀ½ ¸í·ÉÀ¸·Î rpc¼­ºñ½º°¡ ¾øÀ½À» È®ÀÎÇÕ´Ï´Ù.
#rpcinfo -p

3. ¸Þ½ÃÁö È®ÀÎ
Rpcinfo: can¡¯t contact portmapper: RPC: Remote system error
°ü·Ã URL CVE-1999-0168 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 80 (ISS)