| Ãë¾àÁ¡ID |
18014 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ·ÎÄà »ç¿ëÀÚ°¡ root ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸ÀδÙ. Sendmail 8.11.0¿¡¼ 8.11.5, ±×¸®°í 8.12.0 beta 0 ¿¡¼ beta 18ÀÇ ¹öÀüµéÀº µð¹ö±ë ±â´ÉÀÇ ÀԷ Ÿ´ç¼º üŷ°úÁ¤¿¡ ¹®Á¦Á¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº µð¹ö°Å ÀμöµéÀÇ 'category' ºÎºÐ¿¡ À½ÀÇ Á¤¼ö¸¦ °Ç³×ÁÖ¸é ¸Å¿ì Å« ¼ýÀÚ°ªÀ¸·Î ÀÎ½ÄµÇ¸é¼ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ´Â µ¥¿¡ ÀÖ´Ù. ±× ¼ýÀÚ°ªÀº trace vector¿¡ ´ëÇÑ À妽º·Î »ç¿ëµÇ±â ¶§¹®¿¡ À½¼ö°ªÀÌ ÁÖ¾îÁø´Ù¸é ÇÁ·Î¼¼½º ¸Þ¸ð¸®ÀÇ ¾î¶² ¹üÀ§³»¿¡ write ÇÏ·Áµç´Ù. ÇÁ·Î±×·¥ÀÌ »ó½ÂµÈ ±ÇÇÑÀ» ´Ù½Ã ¶³¾î¶ß·Á »ç¿ëÀÚ ±ÇÇÑÀ¸·Î µ¹¾Æ°¡±â Àü¿¡ '-d' ¸í·É¾î ¶óÀÎ Àμö°¡ 󸮵DZ⠶§¹®¿¡ ÀÌ Ãë¾àÁ¡Àº ·ÎÄà »ç¿ëÀÚµéÀÌ »ó½ÂµÈ ±ÇÇÑÀÎ root ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖµµ·Ï ÇØ ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/3163 http://www.sendmail.org/8.11.html |
| ÇØ°áÃ¥ |
Sendmail 8.12beta19 ȤÀº 8.11.6À¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº 8.10 ÀÌÇÏÀÇ ¹öÀüµé¿¡¼´Â Á¸ÀçÇÏÁö ¾Ê´Â´Ù. ±×·¯³ª Ç×»ó ±×·¡¿ÔµíÀÌ ÃֽйöÀüÀ» »ç¿ëÇϱ⸦ ±ÇÀåÇÑ´Ù. ÀÌ ¹®Á¦´Â ¼³¸í¿¡¼µµ ³ª¿ÍÀÖµíÀÌ ¿ø°ÝÀ¸·Î´Â ÇØÅ·ÀÌ °¡´ÉÇÏÁö ¾Ê´Ù. sendmail 8.12´Â µðÆúÆ®·Î set-user-id°¡ rootÀÎ ½ÇÇàÆÄÀÏÀ» ´õÀÌ»ó »ç¿ëÇÏÁö ¾Ê´Â´Ù.
ÀÌ ¹®Á¦°¡ ¼öÁ¤µÈ ¾÷µ¥ÀÌÆ®µÈ ÆÐŰÁöµéÀº ¿©·¯ º¥´õµé·Î ºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Ù:
- Sendmail Consortium upgrade : ftp://ftp.sendmail.org/pub/sendmail/
±× ¿ÜÀÇ ½Ã½ºÅÛµéÀº Vender¿Í »óÀÇÇÏ¿© ÃֽŠSendmail·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0653 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|