| Ãë¾àÁ¡ID |
25013 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
1521 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
Oracle TNS (Transparent Network Substrate) ListenerÀÇ ¹öÀü¿¡ ÀÇÇÏ¸é ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³´Ù. Windows, Linux, Solaris, AIX, HP-UX ±×¸®°í Tru64 Unix¸¦ À§ÇÑ Oracle 8iÀÇ Ç¥ÁØÆÇ°ú ¿£ÅÍÇÁ¶óÀÌÁîÆÇ ¹öÀü 8.1.5, 8.1.6, 8.1.7À» Æ÷ÇÔÇÑ ÀÌÀü ¹öÀüµéÀº ¸ðµÎ Ãë¾àÇÏ´Ù. Oracle TNS Listener´Â ¿ø°ÝÁöÀÇ Oracle µ¥ÀÌŸº£À̽º ¼ºñ½ºµé°ú Åë½ÅÀ» ¸Î°í À¯ÁöÇÏ´Â ¿ªÇÒÀ» ´ã´çÇÑ´Ù. TNS Listener µ¥¸óÀº Windows NT/2000 ¾Æ·¡¿¡¼´Â "LocalSystem" ±ÇÇÑÀ¸·Î, UNIX ¾Æ·¡¿¡¼´Â 'oracle' »ç¿ëÀÚ ±ÇÇÑÀ¸·Î ±âµ¿µÈ´Ù. ±× Listener´Â ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ¿© µ¥ÀÌŸº£À̽º ¼¹ö»óÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¿ø°ÝÀ¸·Î Çã¿ëÇÔÀ¸·Î½á µ¥ÀÌŸº£À̽º ¼ºñ½º¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±Ç°ú ¸î¸î Ç÷§Æû¿¡¼´Â ÇØ´ç ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ÁÙ ¼ö ÀÖ´Ù. ±× ¹öÆÛ ¿À¹öÇ÷οì´Â ÀÎÁõÀÌ ¼öÇàµÇ±â¿¡ ¾Õ¼ ¹ß»ýÇϱ⠶§¹®¿¡ listener´Â ÆÐ½º¿öµå ¼³Á¤¿¡ ÀÇÇÑ º¸È£¿¡ °ü°è¾øÀÌ Ãë¾àÇÏ´Ù. TNS listenetÀÇ °ü¸®¿ë ¸í·É ¹®ÀÚ¿Àº "SERVICE", "VERSION", "USER"¿Í "ARGUMENTS"¿Í °°Àº ¸î¸î Àμö¸¦ Æ÷ÇÔÇÑ´Ù. À̵é ÁßÀÇ ¾î¶² °ÍÀÌ¶óµµ ¿À¹öÇ÷ο츦 ½Ã۱â À§ÇÑ µ¥ÀÌŸ¸¦ ¸¸µé ¼ö ÀÖ´Ù. Windows¿Í UNIX Ç÷§Æû ¸ðµÎ¿¡¼ ½ºÅà ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼öõ ¹ÙÀÌÆ®ÀÇ È®Àå Àμö¸¦ ¸¸µé ¼ö ÀÖ´Ù. ±× ¿À¹öÇ÷οì´Â Net8 ÇÁ·ÎÅäÄÝ¿¡ µû¸¥ ÇÑ ÆÐŶ ¸í·ÉÀ¸·Î °¡´ÉÇÏ´Ù. Ŭ¶óÀÌ¾ðÆ®´Â Àû´çÇÑ Net8 Çì´õ¿Í ÀÓÀÇÀÇ ¸í·É("shellcode")ÀÌ Æ÷ÇÔµÈ ¾ÇÀÇÀûÀÎ ¸í·É ¹®ÀÚ¿À» Æ÷ÇÔÇÏ´Â Type-1 (NSPTCN) ÆÐŶÀ» º¸³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/2941 http://www.pgp.com/research/covert/advisories/050.asp
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: Windows, Linux, Solaris, AIX, HP-UX ±×¸®°í Tru64 Unix¸¦ À§ÇÑ Oracle 8iÀÇ Ç¥ÁØÆÇ°ú ¿£ÅÍÇÁ¶óÀÌÁîÆÇ ¹öÀü 8.1.5, 8.1.6, 8.1.7À» Æ÷ÇÔÇÑ ÀÌÀü ¹öÀüµé Àüü |
| ÇØ°áÃ¥ |
´ÙÀ½ Oracle Technology Network À¥»çÀÌÆ®¿¡ ÀÖ´Â "Frequently Asked Questions about Listener Security Patches"¿¡ ÀÖµíÀÌ ÀÌ Ãë¾àÁ¡¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ´Ù¿î·Îµå ¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: http://technet.oracle.com/deploy/security/pdf/patch_avail.html ÀÌ »çÀÌÆ®·ÎºÎÅÍ Ç÷§Æû¿¡ ´ëÇÑ ¸±¸®Áî¿Í ÆÐÄ¡ Á¦°ø¿©ºÎ¸¦ ¾Ë¾Æº¸±â À§Çؼ´Â "Patch Availability Matrix"¸¦ º¸¸é µÈ´Ù.
¸¸¾à ÆÐÄ¡°¡ Á¦°øµÇÁö ¾Ê´Â´Ù¸é Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á ½Ã½ºÅÛ»óÀÇ ¸ðµç Oracle InstanceµéÀ» Áö¿øÇÏ´Â ÇÑ °³ÀÇ(Single) ÆÐÄ¡µÈ Listener¸¦ ¿î¿µÇÏ´Â ¹æ¹ýÀ» ¸¶·ÃÇÒ ¼ö ÀÖ´Ù. ÀÌ·¸°Ô Çϱâ À§Çؼ ¸ÕÀú º°°³ÀÇ Oracle HomeÀ» ¸¸µé°í º¸¾È¹®Á¦¿¡ ´ëÇØ ÆÐÄ¡°¡ µÈ Oracle ¹öÀüÀ» ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ »õ·Î¿î HomeÀ¸·ÎºÎÅÍ Listener¸¦ ÀÛµ¿½ÃŰ°í º¸È£µÇÁö ¾Ê´Â Homeµé¿¡ ÀÖ´Â InstanceµéÀ» ¼ºñ½ºÇÒ ¼ö ÀÖ´Ù. ÀÌ·¸°Ô Çϱâ À§Çؼ´Â Instanceµé°ú ±×µéÀÇ Oracle HomeµéÀ» »õ·Î¿î ListenerÀÇ sid_list ¼½¼Ç¿¡ Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
µ¿ÀÏ ½Ã½ºÅÛ»óÀÇ ÆÐÄ¡µÇÁö ¾ÊÀº Oracle ¹öÀüµéÀ» ¼ºñ½ºÇϰí ÀÖ´Â 8.1.7.1 listener.oraÀÇ ¿¹Á¦:
LISTENER = (DESCRIPTION = (ADDRESS = (PROTOCOL = TCP)(HOST = hostname)(PORT = 1521)) )
SID_LIST_LISTENER = (SID_LIST = (SID_DESC = (SID_NAME = P817) (ORACLE_HOME = /u01/app/oracle/product/8.1.7.0) ) (SID_DESC = (SID_NAME = P816) (ORACLE_HOME = /u01/app/oracle/product/8.1.6.0) ) ) |
| °ü·Ã URL |
CVE-2001-499 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|