English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18050
À§Çèµµ 30
Æ÷Æ® 110
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù POP3
»ó¼¼¼³¸í ÇØ´ç Qpopper ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ·ÎÄà »ç¿ëÀÚÀÇ .qpopper-options ¼³Á¤ ÆÄÀÏ¿¡ ±ä bulldir Àμö¸¦ ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖÀ» ¼ö ÀÖ´Ù.
Unix ½Ã½ºÅÛµéÀ» À§ÇÑ POP3 ¸ÞÀÏ ¼­¹ö·Î »ç¿ëµÇ´Â Qpopper´Â ÀÚÀ¯·Ó°Ô ÀÌ¿ë °¡´ÉÇÑ Qualcomm¿¡ ÀÇÇØ ¹èÆ÷µÈ °ø°³ ¼Ò½º ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÌ´Ù. »ç¿ëÀÚ ¼³Á¤ ÆÄÀϵéÀ» ó¸®ÇØ ÁÖ±â À§ÇÑ ¿É¼Ç¼¼Æ®¸¦ °¡Áø Qpopper ¹öÀü 4.0.3°ú 4.0.4Àº ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. »ç¿ëÀÚµéÀÇ ¼³Á¤ ÆÄÀÏ¿¡ ÀÖ´Â bulldir Àμö¸¦ ¾ÆÁÖ ±ä ¹®ÀÚ¿­ (256 ¹ÙÀÌÆ® ÀÌ»ó)·Î ¼³Á¤ÇÔÀ¸·Î½á ·ÎÄà »ç¿ëÀÚ´Â bullName (bulletin ¸í) ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç ½Ã½ºÅÛ»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϰųª ¸ÞÀÏ ¼­¹ö¸¦ Å©·¡½¬ ½Ãų ¼öµµ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ Qpopper ¼­¹öÀÇ ¹è³Ê¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2002-04/0388.html
http://www.eudora.com/qpopper/
http://marc.theaimsgroup.com/?l=vuln-dev&m=102003707432457&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Caldera OpenServer 5.0.5
Caldera OpenServer 5.0.6
Qpopper 4.0.3
Qpopper 4.0.4
Unix ¸ðµç ¹öÀü
Linux ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Qualcomm Qpopper ftp »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© QpopperÀÇ °¡Àå ÃֽйöÀü (4.0.5fc2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.qualcomm.com/eudora/servers/unix/popper/beta/

Caldera OpenServer 5.0.5¿Í 5.0.6ÀÇ °æ¿ì:
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ OpenServer·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
http://www.sco.com/support/download.html

±âŸ:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-0889 (CVE)
°ü·Ã URL 4614 (SecurityFocus)
°ü·Ã URL 8949 (ISS)