English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23345
À§Çèµµ 40
Æ÷Æ® 631
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CUPS
»ó¼¼¼³¸í CUPS´Â Ç¥ÁØ ±â¹ÝÀÇ ¿ÀÇ ¼Ò½º ÇÁ¸°Æà ½Ã½ºÅÛÀ̸ç, cups-browsed´Â ³×Æ®¿öÅ© ÇÁ¸°Æà ±â´ÉÀ» Æ÷ÇÔÇÏ°í Àִµ¥, ¿©±â¿¡´Â ÀÚµ¿À¸·Î ÇÁ¸°Æ® ¼­ºñ½º¸¦ ¹ß°ßÇÏ°í °øÀ¯ ÇÁ¸°Å͸¦ Ž»öÇÏ´Â ±â´É µîÀÌ ÀÖ½À´Ï´Ù. cups-browsed´Â INADDR_ANY:631¿¡ ¹ÙÀεùµÇ¾î ¸ðµç ¼Ò½ºÀÇ ÆÐŶÀ» ½Å·ÚÇÏ°Ô µÇ¸ç, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â URL·Î Get-Printer-Attributes IPP ¿äûÀ» º¸³¾ ¼ö ÀÖ½À´Ï´Ù. CVE-2024-47076, CVE-2024-47175, CVE-2024-47177°ú °°Àº ´Ù¸¥ Ãë¾àÁ¡°ú °áÇÕÇϸé, ¾Ç¼º ÇÁ¸°ÅÍ·Î ÀμâÇÒ ¶§ ÀÎÁõ ¾øÀÌ ¿ø°ÝÀ¸·Î ´ë»ó ¸Ó½Å¿¡¼­ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.

- cups-browsed ¡Â 2.0.1Àº UDP INADDR_ANY:631¿¡ ¹ÙÀεùµÇ¾î ¸ðµç ¼Ò½ºÀÇ ÆÐŶÀ» ½Å·ÚÇÏ°í, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â URL·Î Get-Printer-Attributes IPP ¿äûÀ» Æ®¸®°ÅÇÕ´Ï´Ù. (CVE-2024-47176)
- libcupsfilters ¡Â 2.1b1ÀÇ cfGetPrinterAttributes5´Â IPP ¼­¹ö·ÎºÎÅÍ ¹ÝȯµÈ IPP ¼Ó¼ºÀ» °ËÁõÇϰųª Á¤È­ÇÏÁö ¾Ê¾Æ, °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â µ¥ÀÌÅ͸¦ CUPS ½Ã½ºÅÛÀÇ ³ª¸ÓÁö ºÎºÐ¿¡ Á¦°øÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2024-47076)
- libppd ¡Â 2.1b1ÀÇ ppdCreatePPDFromIPP2´Â Àӽà PPD ÆÄÀÏ¿¡ IPP ¼Ó¼ºÀ» ¾µ ¶§ À̸¦ °ËÁõÇϰųª Á¤È­ÇÏÁö ¾Ê¾Æ, »ý¼ºµÈ PPD¿¡ °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â µ¥ÀÌÅ͸¦ ÁÖÀÔÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2024-47175)
- cups-filters ¡Â 2.0.1ÀÇ foomatic-ripÀº FoomaticRIPCommandLine PPD ¸Å°³º¯¼ö¸¦ ÅëÇØ ÀÓÀÇÀÇ ¸í·É ½ÇÇàÀ» Çã¿ëÇÕ´Ï´Ù. (CVE-2024-47177)

* Âü°í »çÀÌÆ®:
https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ * cups-browsed ¼­ºñ½º ºñÈ°¼ºÈ­ (»ç¿ëÇÏÁö ¾ÊÀ» °æ¿ì)
- ¸í·É¾î: $ sudo systemctl stop cups-browsed; sudo systemctl disable cups-browsed
* CUPS ¼­ºñ½º Àç½ÃÀÛ
- ¸í·É¾î: $ sudo systemctl restart cups
* ¹æÈ­º® ¼³Á¤ °­È­
- UDP Æ÷Æ® 631¿¡ ´ëÇÑ ¿ÜºÎ Á¢±Ù Â÷´Ü
- ¸í·É¾î: $ sudo ufw deny proto udp from any to any port 631
°ü·Ã URL CVE-2024-47176,CVE-2024-47076,CVE-2024-47175,CVE-2024-47177 (CVE)
°ü·Ã URL 75098 (SecurityFocus)
°ü·Ã URL (ISS)