English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23146
À§Çèµµ 40
Æ÷Æ® 4105
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í CA Message Queuing ¼­ºñ½ºÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­ºñ½º¿¡´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Computer Associates Message Queuing (CAM/CAFT)´Â ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ½ºÇªÇÎ(spoofing) °ø°Ý ¼öÇà, ÀÓÀÇÀÇ ÄÚµå ½ÇÇà, ¼­ºñ½º °ÅºÎ À¯¹ßÀ» Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù. ù¹ø° Ãë¾àÁ¡Àº °ø°ÝÀÚµéÀÌ CAM TCP Æ÷Æ®·Î ¼­ºñ½º °ÅºÎ °ø°ÝµéÀ» °¡ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. µÎ¹ø° Ãë¾àÁ¡Àº CAM¿¡ ÀÇÇØ ¼öÇàµÈ ºÎÀûÀýÇÑ ¹öÆÛ ±æÀÌ °Ë»ç°¡ ¿øÀÎÀÌ µÇ¸ç ÀÌ´Â °ø°ÝÀÚµéÀÌ SYSTEM ¼öÁØÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¶Áö¸· Ãë¾àÁ¡Àº ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Â CAFT ½ºÇªÇÎ °ø°ÝµéÀÌ °³½ÃµÉ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp
http://www.securitytracker.com/alerts/2005/Aug/1014756.html
http://www.kb.cert.org/vuls/id/619988
http://secunia.com/advisories/16513

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Computer Associates, Message Queuing (CAM / CAFT) ¹öÀü 1.05
Computer Associates, Message Queuing (CAM / CAFT) Build 220_13 ÀÌÀüÀÇ 1.07 ¹öÀüµé
Computer Associates, Message Queuing (CAM / CAFT) Build 29_13 ÀÌÀüÀÇ 1.11 ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Computer Associates »ç´Â CAM 1.05, 1.07 ±×¸®°í 1.11À» À§ÇÑ ÇÑ ¼¼Æ®ÀÇ ÆÐÄ¡µéÀ» ³» ³õ¾Ò´Ù.

´ÙÀ½ CA Message Queuing º¸¾È °øÁö¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡À» À§ÇÑ Fix¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp
°ü·Ã URL CVE-2005-2667,CVE-2005-2668,CVE-2005-2669 (CVE)
°ü·Ã URL 14621,14622,14623 (SecurityFocus)
°ü·Ã URL 21937,21948,21953 (ISS)