| Ãë¾àÁ¡ID |
19005 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
53 |
| ÇÁ·ÎÅäÄÝ |
TCP,UDP |
| ºÐ·ù |
DNS |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹ö¿¡ ÀÖ´Â BINDÀÇ ¹öÀü¿¡ ÀÇÇÏ¸é ´Ù¾çÇÑ buffer overflow °ø°Ý¿¡ Ãë¾àÇÑ ¹öÀüÀÌ´Ù. ÀÌ Ãë¾àÁ¡Àº ÇØÄ¿°¡ BIND ¼¹ö¿Í µ¿ÀÏÇÑ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ´ëºÎºÐÀÇ BINDµéÀº rootÀÇ ±ÇÇÑÀ¸·Î ¼öÇàµÇ°í ÀÖ¾î ±× ¸í·Éµéµµ ´ëºÎºÐ root ±ÇÇÑÀ¸·Î ¼öÇàµÉ °ÍÀÌ´Ù. üũµÈ BIND ¹öÀüÀº ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
1. "tsig bug" : BIND ¹öÀü 8.xµéÀº RFC 2845¿¡ Á¤ÀÇµÈ °Í°ú °°ÀÌ DNS º¸¾ÈÀ» À§ÇÑ "Transaction Signatures(TSIG)ÀÇ ±¸Çö¿¡¼ buffer overflow ¹ö±×¸¦ °¡Áö°í ÀÖ´Ù. DNS ¿äûÀÇ ÃʱâÈ °úÁ¤¿¡¼ overflow°¡ ¹ß»ýÇϱ⠶§¹®¿¡ DNS º¸¾È¼³Á¤¿¡ »ó°ü¾øÀÌ Ãë¾àÇÏ´Ù. * ¹®Á¦ÀÖ´Â ¹öÀüµé : 8.2, 8.2-P1, 8.2.1, 8.2.2-P1, 8.2.2-P2, 8.2.2-P3, 8.2.2-P4, 8.2.2-P5, 8.2.2-P6, 8.2.2-P7, ±×¸®°í ¸ðµç 8.2.3-betaµé
2. "complain bug" : nslookupComplain() ÇÔ¼ö¿¡ ÀÖ´Â sprintf¿¡ ÀÇÇØ »ç¿ëµÇ´Â ¹öÆÛ°¡ overflow¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. * ¹®Á¦ÀÖ´Â ¹öÀüµé : 4.9.3, 4.9.4, 4.9.5, 4.9.5-P1, 4.9.6, 4.9.7, ±×¿Ü BIND 4.9.xÀÇ Ãʱ⠹öÀüµé (BIND 4.9.8ÀÌ»ó ¹öÀüÀº Á¦¿Ü).
¡Ø BIND (Berkeley Internet Name Domain)´Â Internet Software Consortium (www.isc.org)¿¡ ÀÇÇØ ¹èÆ÷µÈ DNS (Domain Name System) ÇÁ·ÎÅäÄÝÀÇ ±¸ÇöÀÌ´Ù.
* Âü°í »çÀÌÆ®: http://www.isc.org/products/BIND/bind-security.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: BIND 9.1 ¹Ì¸¸ ¹öÀü |
| ÇØ°áÃ¥ |
BINDÀÇ °¡Àå ÃÖ±Ù ¸±¸®ÁîÀÎ ¹öÀü 9¿¡¼´Â ÀÌ·¯ÇÑ °ø°ÝµéÀÌ ¹®Á¦µÇÁö ¾Ê´Â´Ù. BIND ¹öÀü 9.1·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ °¡Àå ÁÁ´Ù. ±×·¯³ª »çÁ¤»ó À̰ÍÀÌ ¾î·Á¿ï ¶§¿¡´Â Àû¾îµµ BIND ¹öÀü 8.2.3ȤÀº BIND 4.9.8 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|