| Ãë¾àÁ¡ID |
25015 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
1521 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
ÇØ´ç Oracle TNS Listener´Â SERVICE_CURLOAD ¸í·É¿¡ ÀÇÇÑ ¼ºñ½º°ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. OracleÀÇ TNS Listener ÇÁ·Î±×·¥Àº Oracle µ¥ÀÌÅͺ£À̽º¸¦ À§ÇÑ ¿ø°Ý Á¢¼Ó ¼ºñ½ºÀÌ´Ù. Oracle TNS listener (´ë°³´Â Æ÷Æ® 1521À» »ç¿ë)·Î Á¢¼ÓÇÏ¿© "(CONNECT_DATA=(COMMAND=SERVICE_CURLOAD))" ¸í·ÉÀ» ÁÖ¸é Oracle ¼¹ö´Â ¼º°øÀûÀÎ ½ÇÇàÀ» ¾Ë¸®´Â ¸Þ½ÃÁö·Î ÀÀ´äÇÑ´Ù. ±×·¯³ª, ÀÏ´Ü È£ÃâÀÚ°¡ Á¢¼ÓÀ» Á¾·áÇϸé Listener ¼ºñ½º´Â ¹ÝÀÀÀ» ÇÏÁö ¾Ê´Â´Ù. ÀÌ·¯ÇÑ ¼ºñ½º°ÅºÎ È¿°ú´Â ¾ó¸¶³ª ¿À·¡ °ø°ÝÀÚ°¡ ¿ø·¡ÀÇ Á¢¼ÓÀÌ ¿¬°áµÈ »óŸ¦ À¯ÁöÇÏ´À³Ä¿¡ µû¶ó ´Þ¶óÁø´Ù. ¸¸¾à È£ÃâÀÚ°¡ »õ·Î¿î Á¢¼ÓµéÀÌ ¼ºñ½ºµÇ°í ÀÖÀ» µ¿¾È¿¡ Listener Á¢¼ÓÀ» ¿¬°áÇÑ »óŸ¦ À¯ÁöÇÑ´Ù¸é, ±× Listener ¼ºñ½º´Â Access Violation(¸Þ¸ð¸® ÂüÁ¶ ¿¡·¯)°ú ÇÔ²² Crash°¡ ³ª°Å³ª DisableµÉ °ÍÀÌ´Ù. ¸¸¾à È£ÃâÀÚ°¡ ´Ù¸¥ ¿äûµéÀÌ ¼ºñ½ºµÇ±â Àü¿¡ Listener Á¢¼ÓÀ» Á¾·áÇÑ´Ù¸é Listener ¼ºñ½º´Â »õ·Î¿î Á¢¼Óµé¿¡ ´ëÇÑ ¼ö¿ëÀ» °ÅºÎÇÒ °ÍÀÌ´Ù.
¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ´ÜÁö TNS ListenerÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. ±×·¡¼ Á¡°Ë°á°ú°¡ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)¸¦ º¸ÀÏ ¼ö ÀÖ´Ù.
Ãë¾àÇÑ Ç÷§Æû: Oracle 9i Release 2 (9.2.x) Oracle 9i Release 1 (9.0.x) Oracle 8i (8.1.x)
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/5678 http://www.rapid7.com/advisories/R7-0006.txt |
| ÇØ°áÃ¥ |
º¥´õ Á¦°ø ÆÐÄ¡µéÀ» ´Ù¿î·Îµå¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ ÆÐÄ¡Á¤º¸´Â ´ÙÀ½ Oracle Security Alert #42¿¡¼ º¼ ¼ö ÀÖ´Ù: http://www.oracle.com/technetwork/topics/security/2002alert42rev1-128177.pdf |
| °ü·Ã URL |
CVE-2002-1118 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|