English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18126
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ¹è³Ê¿¡ µû¸£¸é ¿ø°Ý È£½ºÆ®¿¡¼­ ½ÇÇàµÇ´Â Exim ¹öÀüÀº 4.94.2 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼­ ¿ø°Ý ÄÚµå ½ÇÇàÀ¸·Î À̾îÁú ¼ö ÀÖ´Â ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç SMTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://blog.qualys.com/vulnerabilities-research/2021/05/04/21nails-multiple-vulnerabilities-in-exim-mail-server
https://www.qualys.com/2021/05/04/21nails/21nails.txt
https://www.exim.org/static/doc/security/CVE-2020-qualys/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cambridge University, Exim 4.94.2 ÀÌÀü ¹öÀü
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ exim ÆÐÅ°Áö(4.94.2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.exim.org/
°ü·Ã URL CVE-2020-28007,CVE-2020-28008,CVE-2020-28009,CVE-2020-28010,CVE-2020-28011,CVE-2020-28012,CVE-2020-28013,CVE-2020-28014,CVE-2020-28015 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)