Ãë¾àÁ¡ID |
23180 |
À§Çèµµ |
30 |
Æ÷Æ® |
139 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Samba |
»ó¼¼¼³¸í |
Samba ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼¹ö¿¡´Â ·ÎÄà Á¤º¸ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Samba´Â SMB/CIFS Ŭ¶óÀ̾ðÆ®µé¿¡°Ô ¾çÁúÀÇ ÆÄÀÏ ¹× ÇÁ¸°Æ® ¼ºñ½ºµéÀ» Á¦°øÇØ ÁÖ´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¹«·á ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Samba 3.0.21¿¡¼ 3.0.21c±îÁöÀÇ ¹öÀüµéÀº ·ÎÄà °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ Á¤º¸¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. winbindd µ¥¸óÀº Æò¹®À¸·Î ´©±¸³ª Àб⠰¡´ÉÇÑ winbind ·Î±× ÆÄÀϵ鿡 È£½ºÆ®¸¦ ½Å·ÚÇÏ´Â °èÁ¤ ½Å¿ëÁ¤º¸¸¦ ÀúÀåÇÑ´Ù. °ø°ÝÀڴ ȣ½ºÆ®¸¦ ½Å·ÚÇÏ´Â °èÁ¤ ½Å¿ëÁ¤º¸¸¦ ÀÌ¿ëÇÏ¿© µµ¸ÞÀÎ ¼¹ö¸¦ Èä³»³»°í µµ¸ÞÀÎ »ç¿ëÀÚ ¹× ±×·ì°ú´Â °ü°è¾øÀÌ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ´Â ·Î±×¼öÁØÀÌ 5³ª ±× ÀÌ»óÀ¸·Î ¼³Á¤µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Samba ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://us1.samba.org/samba/security/CVE-2006-1059.html http://www.securityfocus.com/archive/1/archive/1/429370/100/0/threaded http://securitytracker.com/id?1015850 http://secunia.com/advisories/19455/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Samba Project, Samba 3.0.21¿¡¼ 3.0.21c±îÁöÀÇ ¹öÀüµé Linux Any version Unix Any version |
ÇØ°áÃ¥ |
Samba À¥ »çÀÌÆ®ÀÎ http://www.samba.org/samba/history/security.html ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â SambaÀÇ °¡Àå ÃֽŠ¹öÀü(3.0.22 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
´Ù¸¥ Á¶Ä¡¹æ¹ýÀ¸·Î´Â µð¹ö±×(Debug) ¼öÁØÀ» 5 ¹Ì¸¸À¸·Î ¼³Á¤ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-1059 (CVE) |
°ü·Ã URL |
17314 (SecurityFocus) |
°ü·Ã URL |
25575 (ISS) |
|