English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23156
À§Çèµµ 40
Æ÷Æ® 105
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í Mercury ph ¼­ºñ½ºÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­ºñ½º¿¡´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Mercury Mail Transport SystemÀº Microsoft Windows¿Í Novell NetWare Ç÷§ÆûµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ Pegasus Mail°ú ¿¬µ¿µÈ ¸ÞÀÏ ¼­¹öÀÌ´Ù. Mercury Mail Transport System ¹öÀü 4.01b°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº "MercuryH PH Directory Server" ÇÁ·ÎÅäÄÝ ¸ðµâ¿¡ ÀÖ´Â ¸ÞÀϹڽº ³×ÀÓ(name) ¼­ºñ½ºÀÇ ºÎÀûÀýÇÑ ¹öÆÛ ±æÀÌ °Ë»ç·Î ÀÎÇÏ¿© ¿ø°Ý ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. TCP Æ÷Æ® 105¹ø »ó¿¡ ÀÖ´Â ¸ÞÀϹڽº ³×ÀÓ ¼­ºñ½º·Î Àß Á¶ÀÛµÈ µ¥ÀÌÅ͸¦ º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Mercury ph ¼­ºñ½ºÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/18611/
http://www.securitytracker.com/alerts/2005/Dec/1015374.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
David Harris, Mercury Mail Transport System ¹öÀü 4.01b°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Pegasus Mail À¥ »çÀÌÆ®ÀÎ http://www.pmail.com/patches.htm ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â 2006³â 1¿ùÀÚ "Mercury/32 Security patches for MercuryW and MercuryH"¸¦ ´Ù¿î·Îµå¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-4411 (CVE)
°ü·Ã URL 16396 (SecurityFocus)
°ü·Ã URL 23669 (ISS)