English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18102
À§Çèµµ 40
Æ÷Æ® 110
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù POP3
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â ¹öÀü 9.0.6 ÀÌÀüÀÇ Alt-N MDaemon POP3 ¼­¹öÀÇ ¹öÀüÀÌ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Alt-N MDaemonÀº Microsoft Windows ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ SMTP/POP/IMAP ¼­¹öÀÌ´Ù. MDaemon 9.0.6 ÀÌÀüÀÇ ¹öÀüµéÀº MDaemon POP3 ¼­¹öÀÇ 'USER' ±×¸®°í 'APOP' ¸í·É ó¸® ºÎºÐ¿¡ ÀÖ´Â Èü ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Ãë¾àÁ¡Àº ¹®ÀÚ¿­¿¡ Æ÷ÇÔµÈ '@' ¹®ÀÚµéÀ» °¡Áø USER³ª APOP ¸í·Éµé¿¡ ±ä ¹®ÀÚ¿­À» Á¦°øÇÔÀ¸·Î½á À¯¹ßµÉ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¾îÇø®ÄÉÀ̼ÇÀÌ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Å³ª POP3 ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç POP3 ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://files.altn.com/MDaemon/Release/RelNotes_en.txt
http://www.infigo.hr/en/in_focus/advisories/INFIGO-2006-08-04
http://www.securityfocus.com/archive/1/444015/30/0/threaded

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Alt-N Technologies »ç, MDaemon 9.0.6 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Alt-N Technologies »çÀÇ À¥ »çÀÌÆ®ÀÎ http://www.altn.com/download/default.asp?product_id=MDaemon ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â MDaemonÀÇ °¡Àå ÃֽŠ¹öÀü(9.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-4364 (CVE)
°ü·Ã URL 19651 (SecurityFocus)
°ü·Ã URL 28517 (ISS)