English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25013
À§Çèµµ 40
Æ÷Æ® 1521
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í Oracle TNS (Transparent Network Substrate) ListenerÀÇ ¹öÀü¿¡ ÀÇÇÏ¸é ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Windows, Linux, Solaris, AIX, HP-UX ±×¸®°í Tru64 Unix¸¦ À§ÇÑ Oracle 8iÀÇ Ç¥ÁØÆÇ°ú ¿£ÅÍÇÁ¶óÀÌÁîÆÇ ¹öÀü 8.1.5, 8.1.6, 8.1.7À» Æ÷ÇÔÇÑ ÀÌÀü ¹öÀüµéÀº ¸ðµÎ Ãë¾àÇÏ´Ù.
Oracle TNS Listener´Â ¿ø°ÝÁöÀÇ Oracle µ¥ÀÌŸº£À̽º ¼­ºñ½ºµé°ú Åë½ÅÀ» ¸Î°í À¯ÁöÇÏ´Â ¿ªÇÒÀ» ´ã´çÇÑ´Ù. TNS Listener µ¥¸óÀº Windows NT/2000 ¾Æ·¡¿¡¼­´Â "LocalSystem" ±ÇÇÑÀ¸·Î, UNIX ¾Æ·¡¿¡¼­´Â 'oracle' »ç¿ëÀÚ ±ÇÇÑÀ¸·Î ±âµ¿µÈ´Ù. ±× Listener´Â ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ¿© µ¥ÀÌŸº£À̽º ¼­¹ö»óÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¿ø°ÝÀ¸·Î Çã¿ëÇÔÀ¸·Î½á µ¥ÀÌŸº£À̽º ¼­ºñ½º¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±Ç°ú ¸î¸î Ç÷§Æû¿¡¼­´Â ÇØ´ç ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ÁÙ ¼ö ÀÖ´Ù. ±× ¹öÆÛ ¿À¹öÇ÷οì´Â ÀÎÁõÀÌ ¼öÇàµÇ±â¿¡ ¾Õ¼­ ¹ß»ýÇϱ⠶§¹®¿¡ listener´Â ÆÐ½º¿öµå ¼³Á¤¿¡ ÀÇÇÑ º¸È£¿¡ °ü°è¾øÀÌ Ãë¾àÇÏ´Ù.
TNS listenetÀÇ °ü¸®¿ë ¸í·É ¹®ÀÚ¿­Àº "SERVICE", "VERSION", "USER"¿Í "ARGUMENTS"¿Í °°Àº ¸î¸î Àμö¸¦ Æ÷ÇÔÇÑ´Ù. À̵é ÁßÀÇ ¾î¶² °ÍÀÌ¶óµµ ¿À¹öÇ÷ο츦 ½Ã۱â À§ÇÑ µ¥ÀÌŸ¸¦ ¸¸µé ¼ö ÀÖ´Ù.
Windows¿Í UNIX Ç÷§Æû ¸ðµÎ¿¡¼­ ½ºÅà ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼öõ ¹ÙÀÌÆ®ÀÇ È®Àå Àμö¸¦ ¸¸µé ¼ö ÀÖ´Ù. ±× ¿À¹öÇ÷οì´Â Net8 ÇÁ·ÎÅäÄÝ¿¡ µû¸¥ ÇÑ ÆÐŶ ¸í·ÉÀ¸·Î °¡´ÉÇÏ´Ù. Ŭ¶óÀÌ¾ðÆ®´Â Àû´çÇÑ Net8 Çì´õ¿Í ÀÓÀÇÀÇ ¸í·É("shellcode")ÀÌ Æ÷ÇÔµÈ ¾ÇÀÇÀûÀÎ ¸í·É ¹®ÀÚ¿­À» Æ÷ÇÔÇÏ´Â Type-1 (NSPTCN) ÆÐŶÀ» º¸³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2941
http://www.pgp.com/research/covert/advisories/050.asp

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Windows, Linux, Solaris, AIX, HP-UX ±×¸®°í Tru64 Unix¸¦ À§ÇÑ Oracle 8iÀÇ Ç¥ÁØÆÇ°ú ¿£ÅÍÇÁ¶óÀÌÁîÆÇ ¹öÀü 8.1.5, 8.1.6, 8.1.7À» Æ÷ÇÔÇÑ ÀÌÀü ¹öÀüµé Àüü
ÇØ°áÃ¥ ´ÙÀ½ Oracle Technology Network À¥»çÀÌÆ®¿¡ ÀÖ´Â "Frequently Asked Questions about Listener Security Patches"¿¡ ÀÖµíÀÌ ÀÌ Ãë¾àÁ¡¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ´Ù¿î·Îµå ¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://technet.oracle.com/deploy/security/pdf/patch_avail.html
ÀÌ »çÀÌÆ®·ÎºÎÅÍ Ç÷§Æû¿¡ ´ëÇÑ ¸±¸®Áî¿Í ÆÐÄ¡ Á¦°ø¿©ºÎ¸¦ ¾Ë¾Æº¸±â À§Çؼ­´Â "Patch Availability Matrix"¸¦ º¸¸é µÈ´Ù.

¸¸¾à ÆÐÄ¡°¡ Á¦°øµÇÁö ¾Ê´Â´Ù¸é Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á ½Ã½ºÅÛ»óÀÇ ¸ðµç Oracle InstanceµéÀ» Áö¿øÇÏ´Â ÇÑ °³ÀÇ(Single) ÆÐÄ¡µÈ Listener¸¦ ¿î¿µÇÏ´Â ¹æ¹ýÀ» ¸¶·ÃÇÒ ¼ö ÀÖ´Ù.
ÀÌ·¸°Ô Çϱâ À§Çؼ­ ¸ÕÀú º°°³ÀÇ Oracle HomeÀ» ¸¸µé°í º¸¾È¹®Á¦¿¡ ´ëÇØ ÆÐÄ¡°¡ µÈ Oracle ¹öÀüÀ» ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ »õ·Î¿î HomeÀ¸·ÎºÎÅÍ Listener¸¦ ÀÛµ¿½ÃŰ°í º¸È£µÇÁö ¾Ê´Â Homeµé¿¡ ÀÖ´Â InstanceµéÀ» ¼­ºñ½ºÇÒ ¼ö ÀÖ´Ù. ÀÌ·¸°Ô Çϱâ À§Çؼ­´Â Instanceµé°ú ±×µéÀÇ Oracle HomeµéÀ» »õ·Î¿î ListenerÀÇ sid_list ¼½¼Ç¿¡ Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

µ¿ÀÏ ½Ã½ºÅÛ»óÀÇ ÆÐÄ¡µÇÁö ¾ÊÀº Oracle ¹öÀüµéÀ» ¼­ºñ½ºÇϰí ÀÖ´Â 8.1.7.1 listener.oraÀÇ ¿¹Á¦:

LISTENER =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = hostname)(PORT = 1521))
)

SID_LIST_LISTENER =
(SID_LIST =
(SID_DESC =
(SID_NAME = P817)
(ORACLE_HOME = /u01/app/oracle/product/8.1.7.0)
)
(SID_DESC =
(SID_NAME = P816)
(ORACLE_HOME = /u01/app/oracle/product/8.1.6.0)
)
)
°ü·Ã URL CVE-2001-499 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)