English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18004
À§Çèµµ 40
Æ÷Æ® 143
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù IMAP
»ó¼¼¼³¸í ÇØ´ç imap¼­¹ö¿¡ buffer overflow ¹ö±×°¡ Á¸ÀçÇÏ¿© ¿ÜºÎ¿¡¼­ ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù. Washington ´ëÇÐÀÇ IMAP¼­¹ö Áß ¼­¹ö·¹º§ÀÇ SASL ÀÎÁõÀ» Áö¿øÇÏ´Â imap-4.1 ÃÖÁ¾ ¹öÀü(º£Å¸Á¦¿Ü) ÀÌÀüÀÇ ¸ðµç ¹öÀüÀÌ Ãë¾àÇÏ´Ù. ±× Ãë¾àÁ¡Àº Washington ´ëÇÐÀÇ v10.234 ÀÌÀüÀÇ ¸ðµç IMAP4rev1 ¼­¹öµé¿¡ ¿µÇâÀ» ¹ÌÄ£´Ù. ¶ÇÇÑ v10.234 ¼­¹ö Á¶Â÷µµ Pine 4.0°ú ÇÔ²² ¹èÆ÷µÇ¾ú´Ù°Å³ª imap-4.1.BETAÀ̸é ÀÌ ¹ö±×¿¡ Ãë¾àÇÏ´Ù.
ºÎ°¡ÀûÀ¸·Î ±× Ãë¾àÁ¡Àº SASL ¼­¹ö·¹º§ ÀÎÁõÀ» ´Ù·ç´Â Washington ´ëÇÐÀÇ IMAP ¼­¹ö·Î ºÎÅÍ À¯·¡µÈ library Äڵ带 »ç¿ëÇÏ´Â ´Ù¸¥ IMAP ¼­¹öµé¿¡µµ Á¸ÀçÇÑ´Ù.
Washington ´ëÇÐ ¼­¹ö¿Í Äڵ带 °øÀ¯ÇÏÁö ¾Ê´Â IMAP ¼­¹öµéÀº Ãë¾àÇÏÁö ¾Ê´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-98.09.imapd.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/177&type=0&nav=sec.sba
http://www.securityfocus.com/bid/130
ÇØ°áÃ¥ Áï½Ã ÃֽйöÀüÀ¸·Î imap ¼­¹ö¸¦ ¾÷±×·¹À̵å ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)