English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 19020
À§Çèµµ 30
Æ÷Æ® 53
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù DNS
»ó¼¼¼³¸í BIND ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ´ÙÁßÀÇ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ISC BIND(Berkeley Internet Name Daemon)´Â DNS (domain name service) ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÑ ¼­¹ö À¯Æ¿¸®Æ¼·Î ÀÎÅÍ³Ý »ó¿¡¼­ ±¤¹üÀ§ÇÏ°Ô »ç¿ëµÈ´Ù. BINDÀÇ 9.2.6-P1 ÀÌÀüÀÇ ¹öÀüµé ±×¸®°í 9.3.2-P1 ÀÌÀüÀÇ 9.3.x ±×¸®°í 9.4.0b2 ÀÌÀüÀÇ 9.4.x ¹öÀüµéÀº Àç±Í ÁúÀǵé°ú RRsets(Resource Record Sets)ÀÌ ¼­¸íµÈ DNSSEC(DNS Security Extensions)¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿©, ´ÙÁßÀÇ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ¼­¹ö¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç DNS ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.isc.org/products/BIND/
http://www.kb.cert.org/vuls/id/697164
http://www.kb.cert.org/vuls/id/915404

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Internet Software Consortium, BIND 9.2.6-P1 ȤÀº 9.2.7rc2 ÀÌÀüÀÇ 9.2.x ¹öÀüµé
Internet Software Consortium, BIND 9.3.2-P1 ȤÀº 9.3.3rc2 ÀÌÀüÀÇ 9.3.x ¹öÀüµé
Internet Software Consortium, BIND 9.4.0b2 ÀÌÀüÀÇ 9.4.x ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Internet Software Consortium (ISC) À¥ »çÀÌÆ®ÀÎ http://www.isc.org/products/BIND/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â BINDÀÇ °¡Àå ÃֽŠ¹öÀü(9.4.0b2 / 9.3.3rc2 / 9.3.2-P1 / 9.2.7rc2 / 9.2.6-P1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian GNU/LinuxÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-1172-1À» ÂüÁ¶ÇÏ¿© BINDÀÇ ±³Á¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2006/dsa-1172

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Announcement GLSA 200609-11À» ÂüÁ¶ÇÏ¿© BINDÀÇ ±³Á¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200609-11.xml
°ü·Ã URL CVE-2006-4095,CVE-2006-4096 (CVE)
°ü·Ã URL 19859 (SecurityFocus)
°ü·Ã URL 28744,28745 (ISS)