English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23246
À§Çèµµ 40
Æ÷Æ® 139
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Samba
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ 4.4.1 ÀÌÀü 4.4.x ¹öÀüÀÇ Samba °¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç ´ÙÀ½ÀÇ ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- Á¶ÀÛµÈ DCE-RPC ÆÐŶÀ» ´Ù·ê ¶§ DCE-RPC Ŭ¶óÀ̾ðÆ®¿¡ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. Man-in-the-middle °ø°ÝÀ¸·Î º¸¾È ¼öÁØÀ» ´Ù¿î ±×·¹À̵å ÇÒ ¼ö ÀÖÀ¸¸ç, ¼­ºñ½º ÀÚ¿øÀ» °í°¥ ½ÃÅ°°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. (CVE-2015-5370)

- NTLMSSP ÀÎÁõ¿¡ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. Man-in-the-middle °ø°ÝÀÚ´Â NTLMSSP_NEGOTIATE_SIGN°ú NTLMSSP_NEGOTIATE_SEALÀ» Ŭ¸®¾î ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-2110)

- NETLOGON °áÇÔÀ¸·Î ÀÎÇÏ¿© º¸¾Èä³Î »ý¼ºÀÌ ½ÇÆÐÇÒ ¼ö ÀÖ´Ù. (CVE-2016-2111)

- ¹«°á¼º º¸È£ ÀýÂ÷¿¡ °áÇÔ¿¡ Á¸ÀçÇØ Man-in-the-middle °ø°ÝÀÚ´Â º¸¾È LDAP ¿¬°áÀ» ºñ º¸¾È ¹öÀüÀ¸·Î ´Ù¿î±×·¹À̵å ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-2112)

- LDAP, HTTP protocolsÀÇ ÀÎÁõ¼­ È®ÀÎ °úÁ¤¿¡ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. (CVE-2016-2113)

- SMB1 Æ÷·ÎÅäÄÝÀ» »ç¿ëÇϴ Ŭ¶óÀ̾ðÆ®¿¡¼­ smb.conf ÆÄÀÏÀÇ 'server signing = mandatory' ¿É¼Ç ó¸® °úÁ¤¿¡ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. Man-in-the-middle °ø°ÝÀÚ´Â ½ºÇªÇÎ °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. (CVE-2016-2114)

- SMB Ŭ¶óÀ̾ðÆ® ¿¬°áÀÇ ¹«°á¼ºÀ» üũÇÒ ¶§ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. (CVE-2016-2115)

- Remote Procedure Call (RPC) ä³ÎÀÇ À߸øµÈ ÀÎÁõ ·¹º§ Çù»ó¿¡ ÀÇÇÏ¿© Security Account Manager (SAM)¿Í Local Security Authority (Domain Policy) (LSAD) ÇÁ·ÎÅäÄÝ¿¡ °áÇÔÀÌ Á¸ÀçÇÑ´Ù. (CVE-2016-2118)

* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Samba ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://www.samba.org/samba/security/CVE-2015-5370.html
https://www.samba.org/samba/security/CVE-2016-2110.html
https://www.samba.org/samba/security/CVE-2016-2111.html
https://www.samba.org/samba/security/CVE-2016-2112.html
https://www.samba.org/samba/security/CVE-2016-2113.html
https://www.samba.org/samba/security/CVE-2016-2114.html
https://www.samba.org/samba/security/CVE-2016-2115.html
https://www.samba.org/samba/security/CVE-2016-2118.html
http://www.samba.org/samba/history/samba-4.4.1.html
http://badlock.org

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba Project, Samba versions 4.4.1 ÀÌÀü 4.4.x ¹öÀü.
Linux Any version
Unix Any version
ÇØ°áÃ¥ Samba À¥ »çÀÌÆ®ÀÎ https://www.samba.org/samba/download/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SambaÀÇ °¡Àå ÃֽŠ¹öÀü (4.4.1 ȤÀº ÀÌÈÄ ¹öÀü)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2015-5370,CVE-2016-2110,CVE-2016-2111,CVE-2016-2112,CVE-2016-2113,CVE-2016-2114,CVE-2016-2115,CVE-2016-2118 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)