| Ãë¾àÁ¡ID |
18032 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
110 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Pop3 |
| »ó¼¼¼³¸í |
ÇØ´ç Qpopper ¹öÀüÀº °ø°ÝÀÚ°¡ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°ÝÀ» ÅëÇÏ¿© Á¶ÀÛµÈ Çì´õ¸¦ °¡Áø ¸Þ½ÃÁö¸¦ ¸¸µé¾î ³¾ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. Qpopper´Â À¯´Ð½º ½Ã½ºÅÛ¿ëÀ¸·Î Ä÷ÄÄ¿¡ ÀÇÇØ ¹èÆ÷µÈ POP3 ¸ÞÀÏ ¼¹öÀÌ´Ù. Qpopper ¹öÀü 2.53°ú 3.0Àº ÀÌ Ãë¾àÁ¡¿¡ ³ëÃâµÇ¾î ÀÖ´Ù. ÀÌ ¹öÀüµéÀº °íÁ¤µÈ 1024 ¹ÙÀÌÆ® ÀÔ·Â ¹öÆÛ·Î ¸Þ½ÃÁö Çì´õ¸¦ ÀоîµéÀ̱â À§ÇØ fgets()¸¦ »ç¿ëÇϸç '\n' ¹®ÀÚ¸¦ ¹Þ°Å³ª 1023 ¹ÙÀÌÆ®°¡ ÀÐÇôÁö´Â °æ¿ì ±× ¹®ÀÚ¿À» ¸®ÅÏÇÑ´Ù. °ø°ÝÀÚ´Â 1023°³ÀÇ ¹®ÀÚ¿Í ³¡ÀÌ '\n'ÀÎ ¸Þ½ÃÁö ¶óÀÎÀ» ÀÌ¿ëÇÏ¿© ÀÌ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃÄÑ Á¶À۵ǰųª À߸øµÈ Çì´õ¸¦ °¡Áø ¸Þ½ÃÁö¸¦ ¸¸µé ¼ö ÀÖ´Ù. ÀÌ Á¶ÀÛµÈ ¸Þ½ÃÁö´Â ³»ºÎ Æò¹® ¸Þ½ÃÁö·Î½á ´Ù·ç¾îÁö°Ô µÇ¸ç ¹ÙÀÌ·¯½º üŷ ¼ÒÇÁÆ®¿þ¾î¿¡ ÀÇÇØ ½ºÄµµÇÁöµµ ¾Ê´Â´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4349.php http://www.securityfocus.com/bid/1133
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
´ÙÀ½ Qualcomm FTP »çÀÌÆ®·Î ºÎÅÍ Qpopper ¹öÀü 3.0.1b2 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.qualcomm.com/eudora/servers/unix/popper/ ¿¡ ÀÖ´Â "Qpopper software archive" |
| °ü·Ã URL |
CVE-2000-0320 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|