English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23342
À§Çèµµ 30
Æ÷Æ® 139
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Samba
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡¼­ ½ÇÇàµÇ´Â Samba ¹öÀüÀº 4.16.10 ÀÌÀüÀÇ 4.16.x, 4.17.9 ÀÌÀüÀÇ 4.17.x ¶Ç´Â 4.18.4 ÀÌÀüÀÇ 4.18.xÀÔ´Ï´Ù. µû¶ó¼­ ´ÙÀ½À» Æ÷ÇÔÇÑ ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÀ» °¡´É¼ºÀÌ ÀÖ½À´Ï´Ù.

- winbindd_pam_auth_crap.cÀÇ ±æÀÌ È®ÀÎÀÌ ºÎÁ·ÇÏ¿© Samba¿¡¼­ ¹üÀ§¸¦ ¹þ¾î³­ Àб⠿À·ù°¡ ¹ß°ßµÇ¾ú½À´Ï´Ù. NTLM ÀÎÁõÀ» ¼öÇàÇÒ ¶§ Ŭ¶óÀ̾ðÆ®´Â ¾Ïȣȭ ¹®Á¦¿¡ ´ëÇØ ¼­¹ö¿¡ ´Ù½Ã ÀÀ´äÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ÀÀ´äÀÇ ±æÀÌ´Â °¡º¯ÀûÀ̸ç Winbind´Â LAN °ü¸®ÀÚ ÀÀ´ä ±æÀ̸¦ È®ÀÎÇÏÁö ¸øÇÕ´Ï´Ù. NTLM ÀÎÁõ¿¡ Winbind¸¦ »ç¿ëÇÏ´Â °æ¿ì ¾ÇÀÇÀûÀ¸·Î Á¦ÀÛµÈ ¿äûÀ¸·Î ÀÎÇØ Winbind¿¡¼­ ¹üÀ§¸¦ ¹þ¾î³­ ÀбⰡ Æ®¸®°ÅµÇ¾î Ãæµ¹ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-2127)

- Spotlight¿ë SambaÀÇ mdssvc RPC ¼­ºñ½º¿¡¼­ ¹«ÇÑ ·çÇÁ Á¶°ÇÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. Ŭ¶óÀ̾ðÆ®°¡ º¸³½ Spotlight mdssvc RPC ÆÐŶÀ» ±¸¹® ºÐ¼®ÇÒ ¶§ ÇÙ½É ¿ª¸¶¼£¸µ ÇÔ¼ö sl_unpack_loop()°¡ ¹è¿­°ú °°Àº ±¸Á¶ÀÇ ¿ä¼Ò ¼ö¸¦ Æ÷ÇÔÇÏ´Â ³×Æ®¿öÅ© ÆÐŶÀÇ Çʵ带 °ËÁõÇÏÁö ¾Ê¾Ò½À´Ï´Ù. Ä«¿îÆ® °ªÀ¸·Î 0À» Àü´ÞÇÏ¸é °ø°Ý¹ÞÀº ÇÔ¼ö´Â CPU¸¦ 100% ¼Ò¸ðÇÏ´Â ¹«ÇÑ ·çÇÁ¿¡¼­ ½ÇÇàµË´Ï´Ù. ÀÌ °áÇÔÀ¸·Î ÀÎÇØ °ø°ÝÀÚ´Â À߸øµÈ Çü½ÄÀÇ RPC ¿äûÀ» ¹ßÇàÇÏ¿© ¹«ÇÑ ·çÇÁ¸¦ Æ®¸®°ÅÇÏ¿© ¼­ºñ½º °ÅºÎ Á¶°ÇÀ» ÃÊ·¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-34966)

- SambaÀÇ SMB2 ÆÐŶ ¼­¸í ¸ÞÄ¿´ÏÁò¿¡¼­ Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. °ü¸®ÀÚ°¡ '¼­¹ö ¼­¸í = Çʼö'·Î ±¸¼ºÇÑ °æ¿ì ¶Ç´Â SMB2 ÆÐŶ ¼­¸íÀÌ ÇʼöÀÎ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡ ´ëÇÑ SMB2 ¿¬°áÀÇ °æ¿ì SMB2 ÆÐŶ ¼­¸íÀÌ ½ÃÇàµÇÁö ¾Ê½À´Ï´Ù. ÀÌ °áÇÔÀ¸·Î ÀÎÇØ °ø°ÝÀÚ´Â ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» °¡·Îä°í Ŭ¶óÀ̾ðÆ®¿Í ¼­¹ö °£ÀÇ SMB2 ¸Þ½ÃÁö¸¦ ¼öÁ¤ÇÏ¿© µ¥ÀÌÅÍ ¹«°á¼º¿¡ ¿µÇâÀ» ÁÖ´Â Áß°£ÀÚ °ø°Ý°ú °°Àº °ø°ÝÀ» ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-3347)

* Âü°í »çÀÌÆ®:
https://www.samba.org/samba/security/CVE-2022-2127.html
https://www.samba.org/samba/security/CVE-2023-3347.html
https://www.samba.org/samba/security/CVE-2023-34966.html
https://www.samba.org/samba/security/CVE-2023-34967.html
https://www.samba.org/samba/security/CVE-2023-34968.html
https://www.samba.org/samba/history/security.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Samba Project, Samba 4.17.9 ÀÌÀüÀÇ 4.17.x ¹öÀü
Linux Any version
Unix Any version
ÇØ°áÃ¥ Upgrade to the latest version of Samba 4.17.9 or later, available from the Samba Web site at https://www.samba.org/samba/download/
°ü·Ã URL CVE-2022-2127,CVE-2023-3347,CVE-2023-34966,CVE-2023-34967,CVE-2023-34968 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)