English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23005
À§Çèµµ 40
Æ÷Æ® 515
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LPD
»ó¼¼¼³¸í ÇØ´ç Solaris ½Ã½ºÅÛ¿¡ Line Printer Daemon (in.lpd)ÀÌ °¡µ¿µÇ°í ÀÖ´Ù. Solaris 2.8 ÀÌÇÏÀÇ ¹öÀüµéÀÇ Line Printer Daemon¿¡ ÀÖ´Â Buffer Overflow´Â ¿ø°ÝÀ¸·Î Attackerµé¿¡°Ô root ±ÇÇÑÀ» Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù.
Solaris BSD print protocol daemonÀº »ç¿ëÀÚ°¡ ¿ø°ÝÀ¸·Î ·ÎÄà ÇÁ¸°Å͸¦ Á¶ÀÛÇÒ ¼ö ÀÖ´Â ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇÑ´Ù. ÇöÀç SolarisÀÇ ¸ðµç ¹öÀüµéÀº µðÆúÆ®·Î in.lpd µ¥¸óÀÌ ¼³Ä¡µÇ¾î ÀÖ°í °¡µ¿µÈ´Ù. in.lpd µ¥¸óÀº 515 Æ÷Æ®À» »ç¿ëÇÑ´Ù. in.lpd µ¥¸óÀº ³×Æ®¿öÅ©¸¦ ÅëÇØ ¹®¼­µéÀ» ÇÁ¸°Æ® ÇÒ·Á´Â ³×Æ®¿öÅ© »ç¿ëÀڵ鿡°Ô È®ÀåµÈ ±â´ÉÀ» Á¦°øÇÑ´Ù. ¹Ù·Î ±× "transfer job" ·çƾ¿¡ °áÇÔÀÌ ÀÖ¾î AttackerµéÀº üŷµÇÁö ¾Ê´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ´Ù. AttackerµéÀº ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© printer daemonÀ» ´Ù¿î½ÃŰ°Å³ª root ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?id=advise80
http://www.securityfocus.com/bid/2894

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Solaris ½Ã½ºÅÛ
ÇØ°áÃ¥ Oracle »ç¿¡ ¹®ÀÇÇÏ¿© ÇØ´ç OS¿¡ ¸Â´Â Patch¸¦ ¼³Ä¡ÇÑ´Ù.

Patch ¹øÈ£´Â ´ÙÀ½ ¸®½ºÆ®¿Í °°´Ù.
106235-09 SunOS 5.6: lp patch
106236-09 SunOS 5.6_x86: lp patch
107115-08 SunOS 5.7: LP patch
107116-08 SunOS 5.7_x86: LP patch
109320-04 SunOS 5.8: LP patch
109321-04 SunOS 5.8_x86: LP patch

ÀÌ Patch°¡ ¼³Ä¡µÇÁö ¾ÊÀº Ãë¾àÇÑ ¸ðµç ½Ã½ºÅ۵鿡 ÀÖ´Â in.lpd µ¥¸óÀ» °¡µ¿ÁßÁö ½Ãų °ÍÀ» ±Ç°íÇÑ´Ù. In.lpd µ¥¸óÀ» Disable ½Ã۱â À§Çؼ­´Â:
1. root·Î ·Î±×ÀÎ ÇÑ´Ù.
2. ÅØ½ºÆ® ¿¡µðÅÍ·Î /etc/inetd.conf¸¦ ¿ÀÇÂÇÑ´Ù.
3. "printer"·Î ½ÃÀÛÇÏ´Â ¶óÀÎÀ» ã´Â´Ù.
4. ÀÌ ¶óÀÎ ¾Õ¿¡ "#" ¹®ÀÚ¸¦ »ðÀÔÇÑ´Ù. (ÁÖ¼®Ã³¸®)
5. inetd¸¦ Àç°¡µ¿ ½ÃŲ´Ù.
°ü·Ã URL CVE-2001-0353 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)