English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23069
À§Çèµµ 40
Æ÷Æ® 873
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù RSYNCD
»ó¼¼¼³¸í ÇØ´ç rsync ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â µð·ºÅ丮 Ž»ö °áÇÔ¿¡ Ãë¾àÇÏ´Ù. ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ Æ÷ÇԵǾî ÀÖ´Â rsync´Â ¿©·¯ È£½ºÆ®µé °£¿¡ ÆÄÀÏÀ» µ¿±âÈ­Çϴµ¥ »ç¿ëµÇ´Â ¸Å¿ì ÀαâÀÖ´Â ÅøÀÌ´Ù. ºñ·Ï µðÆúÆ®·Î ÀÛµ¿µÇÁö´Â ¾ÊÁö¸¸ rsync´Â FTP ¹Ì·¯ »çÀÌÆ®·Î ÆÄÀÏ ¹èÆ÷ ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â µ¥¸óÀ¸·Î¼­ ÀÛµ¿µÉ ¼ö ÀÖ´Ù. Rsync 2.6.1 ¹Ì¸¸ÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ¸ðµâÀÇ °æ·Î ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀϵ鿡 ´ëÇÑ ¾²±â¸¦ Çã¿ëÇÑ´Ù. ¸¸¾à rsync ¼­¹ö°¡ 'chroot' ¿É¼ÇÀ» ÀÌ¿ëÇÏÁö ¾Ê°í Àбâ/¾²±â°¡ Çã¿ëµÈ ¸ðµâÀ» °¡Áø µ¥¸óÀ¸·Î ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼³Á¤ ¸ðµâ °æ·ÎÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀϵ鿡 ´ëÇØ ¾²±â(write)°¡ °¡´ÉÇÏ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¸é °ø°ÝÀÚ´Â ½Ã½ºÅÛ ÆÄÀϵéÀ» Á¶ÀÛÇÒ ¼ö ÀÖ¾î ÀÓÀÇÀÇ ÄÚµåÀÇ ½ÇÇàÀ̳ª ¼­ºñ½º °ÅºÎ¸¦ ¼öÇàÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç rsync ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/11514/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
GNU Project, rsync 2.6.1 ¹Ì¸¸
UNIX Any version
Linux Any version
ÇØ°áÃ¥ rsync ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://samba.org/rsync/download.html ¿¡¼­ rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-499-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö(2.5.5-0.4 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-499


±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á, ¼³Á¤ ÆÄÀÏ(configuration)¿¡¼­ ´ÙÀ½ Áö½ÃÀÚ¸¦ ¼³Á¤ÇÏ¿© root µð·ºÅ丮¸¦ Á¦ÇÑ(chroot)ÇÑ´Ù:
"use chroot = yes"
°ü·Ã URL CVE-2004-0426 (CVE)
°ü·Ã URL 10247 (SecurityFocus)
°ü·Ã URL 16014 (ISS)