English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23182
À§Çèµµ 40
Æ÷Æ® 41524
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù Daemon
»ó¼¼¼³¸í BrightStor Backup Discovery ¼­ºñ½ºÀÇ ¹öÀü¿¡ µû¸£¸é ÇØ´ç ¼­ºñ½º´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé(QO86255)¿¡ Ãë¾àÇÏ´Ù. BrightStor ARCserve BackupÀº ±â¾÷¿ë ¹é¾÷ ÇÁ·Î±×·¥ÀÌ´Ù. ¶ÇÇÑ ÀÚü Discovery ¼­ºñ½º´Â BrightStor ¼­¹öµéÀÇ Á¸À縦 ÆľÇÇÏ°íÀÚ ·ÎÄà ³×Æ®¿öÅ© »ó¿¡ ÀÖ´Â ´Ù¸¥ BrightStor ¼­¹öµé·ÎºÎÅÍÀÇ ºê·Îµåij½ºÆ®(broadcast) ÆÐŶµéÀ» ±â´Ù¸°´Ù. ´ÙÁßÀÇ Computer Associates (CA) BrightStor ARCserve Backup Á¦Ç°µéÀº Message Engine RPC ¼­ºñ½º¿Í Tape Engine ¼­ºñ½º¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »óÀ¸·Î Àß Á¶ÀÛµÈ µ¥ÀÌÅ͸¦ °¡Áø RPC ¿äûµéÀ» º¸³¿À¸·Î½á, ºñÀΰ¡µÈ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ½ÃÅ°°Å³ª SYSTEM ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp
http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0205.html
http://securitytracker.com/alerts/2006/Nov/1017268.html
http://securitytracker.com/alerts/2007/Mar/1017783.html
http://secunia.com/advisories/24009
http://secunia.com/advisories/24512
http://www.kb.cert.org/vuls/id/375353
http://www.kb.cert.org/vuls/id/437300
http://www.kb.cert.org/vuls/id/647273

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Computer Associates, BrightStor ARCserve Backup r11.1
Computer Associates, BrightStor ARCserve Backup r11.5
Computer Associates, BrightStor ARCserve Backup v9.01
Computer Associates, CA Business Protection Suite r2
Computer Associates, CA Business Protection Suite for MS Premium Edition r2
Computer Associates, CA Business Protection Suite for MS Standard Edition r2
Computer Associates, CA Server Protection Suite r2
Computer Associates, BrightStor ARCserve Backup for Windows r11
Computer Associates, BrightStor Enterprise Backup r10.5
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ CA SupportConnect À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ Fix(QO86255)¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp
°ü·Ã URL CVE-2006-6076,CVE-2007-0816,CVE-2007-1447,CVE-2007-1448 (CVE)
°ü·Ã URL 21221,22365,22994 (SecurityFocus)
°ü·Ã URL 33017,30453,32137,33020 (ISS)