English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18052
À§Çèµµ 30
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç Lotus Domino SMTP ¼­¹ö´Â Mail Loop ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
¹®Á¦´Â ´ÙÀ½°ú °°ÀÌ ¸ÞÀÏ ¼Û½ÅÀÚ¿¡ bounce@[127.0.0.1], ¸ÞÀÏ ¼ö½ÅÀÚ¿¡ ·ÎÄà ¼­¹ö¿¡ Á¸ÀçÇÏÁö ¾Ê´Â ÀÓÀÇÀÇ »ç¿ëÀÚ¸¦ ¼³Á¤ÇÑ ¸Þ½ÃÁö¸¦ ¼­¹ö°¡ ¼ö½ÅÇÒ ¶§ ¹ß»ýÇÑ´Ù:

MAIL FROM: <bounce@[127.0.0.1]>
RCPT TO: <nosuchuser@invaild.net>

ÀÌ·¯ÇÑ »óȲÀÌ ¹ß»ýÇÏ¸é ¼­¹ö´Â ¸Þ½ÃÁöµéÀ» Àڽſ¡°Ô °è¼ÓÀûÀÎ ÀçÀü¼Û(bounce)À» ÇÏ·Á°í Çϸ鼭 ¹«ÇÑ ·çÇÁ·Î µé¾î°¡°Ô µÈ´Ù. ÀÌ´Â ½Ã½ºÅÛÀÌ CPU ÀÚ¿øµéÀÇ 100%¸¦ ¼Ò¸ðÇÏ°Ô ¸¸µç´Ù. ÀÌ·¯ÇÑ °ø°ÝÀ¸·ÎºÎÅÍ Á¤»óÀûÀÎ ±â´ÉÀ» ȸº¹ÇÏ°Ô Çϱâ À§Çؼ­´Â, ¼­¹ö°¡ Àç½ÃÀ۵Ǿî¾ß ÇÏ¸ç ¼öµ¿À¸·Î Å¥(queue)¿¡¼­ ¸Þ½ÃÁö¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2001-08/0280.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Lotus Domino 4.6.1¿¡¼­ 5.0.8 ±îÁöÀÇ ¹öÀüµé
HP-UX ¸ðµç ¹öÀü
Linux ¸ðµç ¹öÀü
Solaris ¸ðµç ¹öÀü
OS/2 ¸ðµç ¹öÀü
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ Lotus »çÀÇ ´Ù¿î·Îµå »çÀÌÆ®·ÎºÎÅÍ ¹®Á¦°¡ ÇØ°áµÈ Domino 5.0.9, ȤÀº Lotus DominoÀÇ °¡Àå ÃֽйöÀü(6.0.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www-10.lotus.com/ldd/down.nsf
°ü·Ã URL CVE-2000-1203 (CVE)
°ü·Ã URL 3212 (SecurityFocus)
°ü·Ã URL 7012 (ISS)