English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22392
À§Çèµµ 40
Æ÷Æ® 8008,8009,8010
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Novell SUSE Linux Enterprise ¼­¹ö´Â Èü ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Novell SUSE Linux Enterprise ¼­¹ö´Â ±â¾÷ ±Ô¸ð(enterprise)ÀÇ È¯°æ¿¡¼­ °ø°³ ¼Ò½º ÄÄÇ»ÆÃÀ» À§ÇÑ Ç÷§ÆûÀÌ´Ù. SuSE Enterprise ȤÀº Open Enterprise Server ¹öÀü 9.0¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀ» À§ÇÑ Novell Remote Manager HTTP ¼­ºñ½º´Â Novell Remote Manager ¼­ºñ½º(novell-nrm)¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. À½¼öÀÇ Content-Length Àμö¸¦ °¡Áø HTTP POST ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» µµ¿ëÇÒ ¼ö ÀÖÀ¸¸ç ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. 'httpstkd' ¼­ºñ½º°¡ root ±ÇÇÑÀ» °¡Áö°í ½ÇÇàµÇ±â ¶§¹®¿¡ °ø°ÝÀڴ ȣ½ºÆ®ÀÇ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾òÀ» ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2006-01/0214.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Novell Open Enterprise Server Any version
SuSE Linux Enterprise Server 9
ÇØ°áÃ¥ ´ÙÀ½ SUSE Security Announcement SUSE-SA:2006:002¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Novell Remote Manager (novell-nrm) ¼­ºñ½º¸¦ À§ÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.novell.com/linux/security/advisories/2006_02_novellnrm.html
°ü·Ã URL CVE-2005-3655 (CVE)
°ü·Ã URL 16226 (SecurityFocus)
°ü·Ã URL 24111 (ISS)