Ãë¾àÁ¡ID |
23345 |
À§Çèµµ |
40 |
Æ÷Æ® |
631 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CUPS |
»ó¼¼¼³¸í |
CUPS´Â Ç¥ÁØ ±â¹ÝÀÇ ¿ÀÇ ¼Ò½º ÇÁ¸°Æà ½Ã½ºÅÛÀ̸ç, cups-browsed´Â ³×Æ®¿öÅ© ÇÁ¸°Æà ±â´ÉÀ» Æ÷ÇÔÇÏ°í Àִµ¥, ¿©±â¿¡´Â ÀÚµ¿À¸·Î ÇÁ¸°Æ® ¼ºñ½º¸¦ ¹ß°ßÇÏ°í °øÀ¯ ÇÁ¸°Å͸¦ Ž»öÇÏ´Â ±â´É µîÀÌ ÀÖ½À´Ï´Ù. cups-browsed´Â INADDR_ANY:631¿¡ ¹ÙÀεùµÇ¾î ¸ðµç ¼Ò½ºÀÇ ÆÐŶÀ» ½Å·ÚÇÏ°Ô µÇ¸ç, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â URL·Î Get-Printer-Attributes IPP ¿äûÀ» º¸³¾ ¼ö ÀÖ½À´Ï´Ù. CVE-2024-47076, CVE-2024-47175, CVE-2024-47177°ú °°Àº ´Ù¸¥ Ãë¾àÁ¡°ú °áÇÕÇϸé, ¾Ç¼º ÇÁ¸°ÅÍ·Î ÀμâÇÒ ¶§ ÀÎÁõ ¾øÀÌ ¿ø°ÝÀ¸·Î ´ë»ó ¸Ó½Å¿¡¼ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
- cups-browsed ¡Â 2.0.1Àº UDP INADDR_ANY:631¿¡ ¹ÙÀεùµÇ¾î ¸ðµç ¼Ò½ºÀÇ ÆÐŶÀ» ½Å·ÚÇÏ°í, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â URL·Î Get-Printer-Attributes IPP ¿äûÀ» Æ®¸®°ÅÇÕ´Ï´Ù. (CVE-2024-47176) - libcupsfilters ¡Â 2.1b1ÀÇ cfGetPrinterAttributes5´Â IPP ¼¹ö·ÎºÎÅÍ ¹ÝȯµÈ IPP ¼Ó¼ºÀ» °ËÁõÇϰųª Á¤ÈÇÏÁö ¾Ê¾Æ, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â µ¥ÀÌÅ͸¦ CUPS ½Ã½ºÅÛÀÇ ³ª¸ÓÁö ºÎºÐ¿¡ Á¦°øÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2024-47076) - libppd ¡Â 2.1b1ÀÇ ppdCreatePPDFromIPP2´Â Àӽà PPD ÆÄÀÏ¿¡ IPP ¼Ó¼ºÀ» ¾µ ¶§ À̸¦ °ËÁõÇϰųª Á¤ÈÇÏÁö ¾Ê¾Æ, »ý¼ºµÈ PPD¿¡ °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â µ¥ÀÌÅ͸¦ ÁÖÀÔÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2024-47175) - cups-filters ¡Â 2.0.1ÀÇ foomatic-ripÀº FoomaticRIPCommandLine PPD ¸Å°³º¯¼ö¸¦ ÅëÇØ ÀÓÀÇÀÇ ¸í·É ½ÇÇàÀ» Çã¿ëÇÕ´Ï´Ù. (CVE-2024-47177)
* Âü°í »çÀÌÆ®: https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8 https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
ÇØ°áÃ¥ |
* cups-browsed ¼ºñ½º ºñÈ°¼ºÈ (»ç¿ëÇÏÁö ¾ÊÀ» °æ¿ì) - ¸í·É¾î: $ sudo systemctl stop cups-browsed; sudo systemctl disable cups-browsed * CUPS ¼ºñ½º Àç½ÃÀÛ - ¸í·É¾î: $ sudo systemctl restart cups * ¹æȺ® ¼³Á¤ °È - UDP Æ÷Æ® 631¿¡ ´ëÇÑ ¿ÜºÎ Á¢±Ù Â÷´Ü - ¸í·É¾î: $ sudo ufw deny proto udp from any to any port 631 |
°ü·Ã URL |
CVE-2024-47176,CVE-2024-47076,CVE-2024-47175,CVE-2024-47177 (CVE) |
°ü·Ã URL |
75098 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|