English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23189
À§Çèµµ 40
Æ÷Æ® 41524
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù Daemon
»ó¼¼¼³¸í BrightStor Backup Discovery ¼­ºñ½ºÀÇ ¹öÀü¿¡ µû¸£¸é ÇØ´ç ¼­ºñ½º´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé(QO87569)¿¡ Ãë¾àÇÏ´Ù. BrightStor ARCserve BackupÀº ±â¾÷¿ë ¹é¾÷ ÇÁ·Î±×·¥ÀÌ´Ù. ¶ÇÇÑ ÀÚü Discovery ¼­ºñ½º´Â BrightStor ¼­¹öµéÀÇ Á¸À縦 ÆľÇÇÏ°íÀÚ ·ÎÄà ³×Æ®¿öÅ© »ó¿¡ ÀÖ´Â ´Ù¸¥ BrightStor ¼­¹öµé·ÎºÎÅÍÀÇ ºê·Îµåij½ºÆ®(broadcast) ÆÐŶµéÀ» ±â´Ù¸°´Ù. ´ÙÁßÀÇ Computer Associates (CA) BrightStor ARCserve Backup Á¦Ç°µéÀº Mediasrv RPC ¼­ºñ½º¿¡ ÀÖ´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »óÀ¸·Î Àß Á¶ÀÛµÈ µ¥ÀÌÅ͸¦ °¡Áø RPC ¿äûµéÀ» º¸³¿À¸·Î½á, ºñÀΰ¡µÈ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ½ÃÅ°°Å³ª SYSTEM ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp
https://www.zerodayinitiative.com/advisories/ZDI-07-022.html
http://archives.neohapsis.com/archives/bugtraq/2007-03/0418.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053266.html
http://www.kb.cert.org/vuls/id/151305
http://www.kb.cert.org/vuls/id/979825
http://securitytracker.com/alerts/2007/Mar/1017830.html
http://securitytracker.com/alerts/2007/Apr/1017952.html
http://secunia.com/advisories/24682
http://secunia.com/advisories/24972

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Computer Associates, BrightStor ARCserve Backup r11.1
Computer Associates, CA Business Protection Suite r2
Computer Associates, CA Business Protection Suite for MS Premium Edition r2
Computer Associates, CA Business Protection Suite for MS Standard Edition r2
Computer Associates, CA Server Protection Suite r2
Computer Associates, BrightStor ARCserve Backup r11.5
Computer Associates, BrightStor ARCserve Backup r11.5 SP2
Computer Associates, BrightStor ARCserve Backup for Windows 9.01
Computer Associates, BrightStor ARCserve Backup for Windows r11
Computer Associates, BrightStor Enterprise Backup r10.5
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ CA SupportConnect À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ Fix(QO87569)¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp
°ü·Ã URL CVE-2007-1785,CVE-2007-2139 (CVE)
°ü·Ã URL 23209,23635 (SecurityFocus)
°ü·Ã URL 33316,33854 (ISS)