| Ãë¾àÁ¡ID |
18054 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é Á¶ÀÛµÈ ÁÖ¼Ò ÇʵåµéÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡(3)À» °¡Áö°í ÀÖ´Ù. SendmailÀº ¸Å¿ì ±¤¹üÀ§ÇÏ°Ô Ã¤ÅÃµÈ Mail Transport Agent (MTA)ÀÌ´Ù. ¸¹Àº UNIX¿Í Linux ½Ã½ºÅÛµéÀÌ µðÆúÆ®·Î žÀçµÇ¾î ÀÛµ¿ÇÏ´Â Sendmail ±¸ÇöÀ» Á¦°øÇÑ´Ù. Sendmail 8.12.9 ÀÌÇÏÀÇ ¹öÀüµé¿¡ ÀÖ´Â prescan ÇÔ¼ö´Â ÁÖ¼Ò ÇØ¼®(parsing) Äڵ忡 Ãë¾àÁ¡À» Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº CA-2003-12¿¡ ¼³¸íµÈ °Í°ú´Â ´Ù¸£´Ù. ¸¸¾à ºñÇ¥ÁØÀÇ RulesetµéÀÎ (1) recipient, (2) final, ȤÀº (3) mailer-specific envelope recipients(¼Û½ÅÀÚ-ÁöÁ¤ Envelope ¼ö½Åó)°¡ »ç¿ëµÈ´Ù¸é, ±×¸®°í À̵éÀÌ µðÆúÆ®·Î ¾Æ¹«·± ¼³Á¤µµ µÇ¾î ÀÖÁö ¾Ê´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç Sendmail µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½ÃŰ°Å³ª ¼ºñ½º °ÅºÎ¸¦ À¯¹ß½Ãų ¼ö ÀÖ´Ù. ¸¸¾à RunAsUser ¿É¼ÇÀÌ ¼³Á¤µÇ¾î ÀÖÁö ¾Ê´Ù¸é SendmailÀº ÀüÇüÀûÀ¸·Î root·Î ÀÛµ¿ÇÑ´Ù.
* ¾Ë¸² : ´ÙÀ½°ú °°Àº ÀÌÀ¯·Î ÀÎÇÏ¿©, ÀÌ Ãë¾àÁ¡Àº »ç¿ëÀÚÀÇ È¯°æ¿¡¼ º¸¾È À§Çù¿ä¼Ò°¡ µÉ ¼öµµ ÀÖ°í ±×·¸Áö ¾ÊÀ» ¼öµµ ÀÖ´Ù. (Áï, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼öµµ ÀÖ´Ù) 1. ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡ Á¡°ËÀ» À§ÇØ Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ ÀÇÁ¸ÇÑ´Ù. 2. Á¡°Ë¿¡ ÀÌ¿ëµÇ´Â Sendmail ¼¹öÀÇ ¹öÀü Á¤º¸´Â Sendmail ÄÁ¼Ò½Ã¾ö¿¡¼ ¸±¸®ÁîÇÑ Ç¥ÁØ Sendmail ¹èÆ÷ÆÇ¿¡ ±Ù°ÅÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-2003-25.html http://www.sendmail.org/8.12.10.html http://www.securiteam.com/unixfocus/5NP0B2AB5W.html http://marc.theaimsgroup.com/?l=bugtraq&m=106381604923204&w=2 http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0113.html http://xforce.iss.net/xforce/alerts/id/advise142 http://lists.netsys.com/pipermail/full-disclosure/2003-September/010287.html http://www.kb.cert.org/vuls/id/784980#systems
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sendmail 8.12.9 ÀÌÇÏ Linux Any version UNIX Any version ƯÁ¤ º¥´õµé¿¡ ´ëÇÑ Á¤º¸¿¡ ´ëÇØ¼´Â À§ÀÇ 'Âü°í »çÀÌÆ®'¿¡ ÀÖ´Â VU#784980ÀÇ Systems Affected ¼½¼Ç Âü°í |
| ÇØ°áÃ¥ |
´ÙÀ½ Sendmail À¥ »çÀÌÆ®ÀÇ "Sendmail 8.12.10"À» Âü°íÇÏ¿© SendmailÀÇ °¡Àå ÃֽйöÀü(8.12.10 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: http://www.sendmail.org/8.12.10.html
Sun Solaris 7, 8 ±×¸®°í 9ÀÇ °æ¿ì: https://support.oracle.com/ ¿¡¼ ÇØ´ç ÆÐÄ¡¸¦ ´Ù¿î·Îµå ÇÏ¿© ¼³Ä¡ÇÑ´Ù. Oracle»ç¿¡¼ ÇØ´ç ÆÐÄ¡¸¦ Áö¿øÇÏÁö ¾Ê´Â °æ¿ì º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. Sun Solaris 7.0 : 107684-10 Sun Solaris 8_sparc : 110615-10
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-384-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ sendmail ÆÐŰÁö (8.12.3-6.6 ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2003/dsa-384
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2003:283-09¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ sendmail ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2003-283.html
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ Mandrake Linux º¸¾È ±Ç°í¾È MDKSA-2003:092¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ sendmail ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡¸¦ ¾Ë¾Æº¸¾Æ¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT ±Ç°í¾ÈÀ» Âü°íÇ϶ó: http://www.kb.cert.org/vuls/id/784980#systems |
| °ü·Ã URL |
CVE-2003-0694 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
13216 (ISS) |
|