|  Ãë¾àÁ¡ID  | 
	             23086  | 
             
             
 	            |  À§Çèµµ  | 
	             40  |  
             
            
 	            |  Æ÷Æ®  | 
	             873  | 
             		
            	
 	            |  ÇÁ·ÎÅäÄÝ  | 
	             TCP  | 
             	
            	
 	            |  ºÐ·ù  | 
	             RSYNCD  | 
             			
            	
 	            |  »ó¼¼¼³¸í  | 
	             ÇØ´ç rsync ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â µð·ºÅ丮 Ž»ö °áÇÔ¿¡ Ãë¾àÇÏ´Ù. ´ëºÎºÐÀÇ Linux ¹èÆ÷ÆÇ¿¡ Æ÷ÇԵǾî ÀÖ´Â rsync´Â ¿©·¯ È£½ºÆ®µé °£¿¡ ÆÄÀÏÀ» µ¿±âÈÇϴµ¥ »ç¿ëµÇ´Â ¸Å¿ì ÀαâÀÖ´Â ÅøÀÌ´Ù. ºñ·Ï µðÆúÆ®·Î ÀÛµ¿µÇÁö´Â ¾ÊÁö¸¸ rsync´Â FTP ¹Ì·¯ »çÀÌÆ®·Î ÆÄÀÏ ¹èÆ÷ ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â µ¥¸óÀ¸·Î¼ ÀÛµ¿µÉ ¼ö ÀÖ´Ù. Rsync 2.6.2 ÀÌÇÏ ¹öÀüµé ¿ëÀÇ util.c ÆÄÀÏ ³»ÀÇ sanitize_path ÇÔ¼ö¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº chroot°¡ ÀÛµ¿µÇ°í ÀÖÁö ¾ÊÀ» ¶§, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ rsyncÀÇ ±ÇÇÑÀ¸·Î Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÆÄÀϵéÀ» º¸°Å³ª ¾µ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
  * ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç rsync ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
  * Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Aug/1010940.html
  * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: GNU Project, rsync 2.6.3 ¹Ì¸¸ UNIX Any version Linux Any version  | 
             
            	
 	            |  ÇØ°áÃ¥  | 
	             rsync ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://samba.org/rsync/download.html ¿¡¼ rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.3 ȤÀº ÀÌÈÄ)ÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ À̸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
  Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Security Advisory RHSA-2004:436-07À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2004-436.html
  SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SuSE-SUSE-SA:2004:026À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_26_rsync.html
  Debian GNU/Linux 3.0 (alias woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-538-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö(2.5.5-0.6 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-538
  Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200408-17À» ÂüÁ¶ÇÏ¿© rsyncÀÇ °¡Àå ÃֽйöÀü(2.6.0-r3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200408-17.xml
  Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:083À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ rsync ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
  ±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.  |   
             		
            	
 	            |  °ü·Ã URL  | 
	             CVE-2004-0792 (CVE) | 
             		
            	
 	            |   °ü·Ã URL  | 
	            10938 (SecurityFocus) |  
             
            
 	            |   °ü·Ã URL  | 
	            16975 (ISS) | 
             
    	
         
         |