English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18089
À§Çèµµ 30
Æ÷Æ® 110
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù POP3
»ó¼¼¼³¸í Qpopper POP3 ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â µÎ °³ÀÇ ¾ÈÀüÇÏÁö ¾ÊÀº ÆÄÀÏ Ãë±Þ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Qpopper´Â Qualcomm»ç¿¡ ÀÇÇØ ¹èÆ÷µÈ POP3 ¸ÞÀÏ ¼­¹ö·Î¼­, Unix ½Ã½ºÅÛµé ¿ëÀ¸·Î ÀÚÀ¯·Ó°Ô ÀÌ¿ë °¡´ÉÇÏ´Ù. Qpopper 4.0.5 ÀÌÇÏÀÇ ¹öÀüµéÀº µÎ °³ÀÇ ·ÎÄÿ¡¼­ ¹®Á¦µÇ´Â, ¾ÈÀüÇÏÁö ¾ÊÀº ÆÄÀÏ Ãë±Þ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¾ÇÀÇÀûÀÎ ·ÎÄà »ç¿ëÀÚµéÀÌ »ó½ÂµÈ ±ÇÇÑÀ» °¡Áö°í ¾î¶² ÇàÀ§µéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:

1) »ç¿ëÀÚ°¡ Á¦°øÇÑ config¿Í trace ÆÄÀϵéÀ» »ó½ÂµÈ ±ÇÇÑÀ» °¡Áö°í ó¸®ÇÏ´Â ºÎºÐ¿¡ ÀÖ´Â ¿¡·¯´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» »ý¼º ȤÀº µ¤¾î¾²±â ÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) ¾Ë·ÁÁöÁö ¾ÊÀº ¿¡·¯´Â ±×·ìÀ̳ª ´©±¸³ª ¾²±â °¡´ÉÇÑ ÆÄÀϵéÀ» »ý¼ºÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç POP3 ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/15475/
http://archives.neohapsis.com/archives/bugtraq/2005-05/0293.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Qualcomm, Qpopper 4.0.5 ÀÌÇÏÀÇ ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ Qualcomm À¥ »çÀÌÆ®ÀÎ http://www.eudora.com/qpopper/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â QpopperÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-728-1À» ÂüÁ¶ÇÏ¿© qpopperÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.4-2.woody ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2005/dsa-728

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Summary Report SUSE-SR:2005:014¸¦ ÂüÁ¶ÇÏ¿© SuSE FTP ¼­¹ö ȤÀº YaST Online Update¸¦ °æÀ¯ÇÏ¿© ÀûÀýÇÑ FixµÈ ÆÐÅ°ÁöµéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2005_14_sr.html
°ü·Ã URL CVE-2005-1151,CVE-2005-1152 (CVE)
°ü·Ã URL 13714 (SecurityFocus)
°ü·Ã URL 20760,20762 (ISS)