Ãë¾àÁ¡ID |
23069 |
À§Çèµµ |
40 |
Æ÷Æ® |
873 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
RSYNCD |
»ó¼¼¼³¸í |
ÇØ´ç rsync ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â µð·ºÅ丮 Ž»ö °áÇÔ¿¡ Ãë¾àÇÏ´Ù. ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ Æ÷ÇԵǾî ÀÖ´Â rsync´Â ¿©·¯ È£½ºÆ®µé °£¿¡ ÆÄÀÏÀ» µ¿±âÈÇϴµ¥ »ç¿ëµÇ´Â ¸Å¿ì ÀαâÀÖ´Â ÅøÀÌ´Ù. ºñ·Ï µðÆúÆ®·Î ÀÛµ¿µÇÁö´Â ¾ÊÁö¸¸ rsync´Â FTP ¹Ì·¯ »çÀÌÆ®·Î ÆÄÀÏ ¹èÆ÷ ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â µ¥¸óÀ¸·Î¼ ÀÛµ¿µÉ ¼ö ÀÖ´Ù. Rsync 2.6.1 ¹Ì¸¸ÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ¸ðµâÀÇ °æ·Î ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀϵ鿡 ´ëÇÑ ¾²±â¸¦ Çã¿ëÇÑ´Ù. ¸¸¾à rsync ¼¹ö°¡ 'chroot' ¿É¼ÇÀ» ÀÌ¿ëÇÏÁö ¾Ê°í Àбâ/¾²±â°¡ Çã¿ëµÈ ¸ðµâÀ» °¡Áø µ¥¸óÀ¸·Î ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼³Á¤ ¸ðµâ °æ·ÎÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀϵ鿡 ´ëÇØ ¾²±â(write)°¡ °¡´ÉÇÏ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¸é °ø°ÝÀÚ´Â ½Ã½ºÅÛ ÆÄÀϵéÀ» Á¶ÀÛÇÒ ¼ö ÀÖ¾î ÀÓÀÇÀÇ ÄÚµåÀÇ ½ÇÇàÀ̳ª ¼ºñ½º °ÅºÎ¸¦ ¼öÇàÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç rsync ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/advisories/11514/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: GNU Project, rsync 2.6.1 ¹Ì¸¸ UNIX Any version Linux Any version |
ÇØ°áÃ¥ |
rsync ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://samba.org/rsync/download.html ¿¡¼ rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-499-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö(2.5.5-0.4 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-499
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á, ¼³Á¤ ÆÄÀÏ(configuration)¿¡¼ ´ÙÀ½ Áö½ÃÀÚ¸¦ ¼³Á¤ÇÏ¿© root µð·ºÅ丮¸¦ Á¦ÇÑ(chroot)ÇÑ´Ù: "use chroot = yes" |
°ü·Ã URL |
CVE-2004-0426 (CVE) |
°ü·Ã URL |
10247 (SecurityFocus) |
°ü·Ã URL |
16014 (ISS) |
|