Ãë¾àÁ¡ID |
18089 |
À§Çèµµ |
30 |
Æ÷Æ® |
110 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
POP3 |
»ó¼¼¼³¸í |
Qpopper POP3 ¼¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼¹ö¿¡´Â µÎ °³ÀÇ ¾ÈÀüÇÏÁö ¾ÊÀº ÆÄÀÏ Ãë±Þ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Qpopper´Â Qualcomm»ç¿¡ ÀÇÇØ ¹èÆ÷µÈ POP3 ¸ÞÀÏ ¼¹ö·Î¼, Unix ½Ã½ºÅÛµé ¿ëÀ¸·Î ÀÚÀ¯·Ó°Ô ÀÌ¿ë °¡´ÉÇÏ´Ù. Qpopper 4.0.5 ÀÌÇÏÀÇ ¹öÀüµéÀº µÎ °³ÀÇ ·ÎÄÿ¡¼ ¹®Á¦µÇ´Â, ¾ÈÀüÇÏÁö ¾ÊÀº ÆÄÀÏ Ãë±Þ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¾ÇÀÇÀûÀÎ ·ÎÄà »ç¿ëÀÚµéÀÌ »ó½ÂµÈ ±ÇÇÑÀ» °¡Áö°í ¾î¶² ÇàÀ§µéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:
1) »ç¿ëÀÚ°¡ Á¦°øÇÑ config¿Í trace ÆÄÀϵéÀ» »ó½ÂµÈ ±ÇÇÑÀ» °¡Áö°í ó¸®ÇÏ´Â ºÎºÐ¿¡ ÀÖ´Â ¿¡·¯´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» »ý¼º ȤÀº µ¤¾î¾²±â ÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 2) ¾Ë·ÁÁöÁö ¾ÊÀº ¿¡·¯´Â ±×·ìÀ̳ª ´©±¸³ª ¾²±â °¡´ÉÇÑ ÆÄÀϵéÀ» »ý¼ºÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç POP3 ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/advisories/15475/ http://archives.neohapsis.com/archives/bugtraq/2005-05/0293.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Qualcomm, Qpopper 4.0.5 ÀÌÇÏÀÇ ¹öÀüµé Linux Any version Unix Any version |
ÇØ°áÃ¥ |
Qualcomm À¥ »çÀÌÆ®ÀÎ http://www.eudora.com/qpopper/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â QpopperÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-728-1À» ÂüÁ¶ÇÏ¿© qpopperÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.4-2.woody ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2005/dsa-728
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Summary Report SUSE-SR:2005:014¸¦ ÂüÁ¶ÇÏ¿© SuSE FTP ¼¹ö ȤÀº YaST Online Update¸¦ °æÀ¯ÇÏ¿© ÀûÀýÇÑ FixµÈ ÆÐÅ°ÁöµéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2005_14_sr.html |
°ü·Ã URL |
CVE-2005-1151,CVE-2005-1152 (CVE) |
°ü·Ã URL |
13714 (SecurityFocus) |
°ü·Ã URL |
20760,20762 (ISS) |
|