English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23180
À§Çèµµ 30
Æ÷Æ® 139
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Samba
»ó¼¼¼³¸í Samba ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ·ÎÄà Á¤º¸ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Samba´Â SMB/CIFS Ŭ¶óÀ̾ðÆ®µé¿¡°Ô ¾çÁúÀÇ ÆÄÀÏ ¹× ÇÁ¸°Æ® ¼­ºñ½ºµéÀ» Á¦°øÇØ ÁÖ´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¹«·á ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Samba 3.0.21¿¡¼­ 3.0.21c±îÁöÀÇ ¹öÀüµéÀº ·ÎÄà °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ Á¤º¸¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. winbindd µ¥¸óÀº Æò¹®À¸·Î ´©±¸³ª Àб⠰¡´ÉÇÑ winbind ·Î±× ÆÄÀϵ鿡 È£½ºÆ®¸¦ ½Å·ÚÇÏ´Â °èÁ¤ ½Å¿ëÁ¤º¸¸¦ ÀúÀåÇÑ´Ù. °ø°ÝÀڴ ȣ½ºÆ®¸¦ ½Å·ÚÇÏ´Â °èÁ¤ ½Å¿ëÁ¤º¸¸¦ ÀÌ¿ëÇÏ¿© µµ¸ÞÀÎ ¼­¹ö¸¦ Èä³»³»°í µµ¸ÞÀÎ »ç¿ëÀÚ ¹× ±×·ì°ú´Â °ü°è¾øÀÌ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ­´Â ·Î±×¼öÁØÀÌ 5³ª ±× ÀÌ»óÀ¸·Î ¼³Á¤µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Samba ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://us1.samba.org/samba/security/CVE-2006-1059.html
http://www.securityfocus.com/archive/1/archive/1/429370/100/0/threaded
http://securitytracker.com/id?1015850
http://secunia.com/advisories/19455/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba Project, Samba 3.0.21¿¡¼­ 3.0.21c±îÁöÀÇ ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ Samba À¥ »çÀÌÆ®ÀÎ http://www.samba.org/samba/history/security.html ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SambaÀÇ °¡Àå ÃֽŠ¹öÀü(3.0.22 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

´Ù¸¥ Á¶Ä¡¹æ¹ýÀ¸·Î´Â µð¹ö±×(Debug) ¼öÁØÀ» 5 ¹Ì¸¸À¸·Î ¼³Á¤ÇÑ´Ù.
°ü·Ã URL CVE-2006-1059 (CVE)
°ü·Ã URL 17314 (SecurityFocus)
°ü·Ã URL 25575 (ISS)