English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25015
À§Çèµµ 30
Æ÷Æ® 1521
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç Oracle TNS Listener´Â SERVICE_CURLOAD ¸í·É¿¡ ÀÇÇÑ ¼­ºñ½º°ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. OracleÀÇ TNS Listener ÇÁ·Î±×·¥Àº Oracle µ¥ÀÌÅͺ£À̽º¸¦ À§ÇÑ ¿ø°Ý Á¢¼Ó ¼­ºñ½ºÀÌ´Ù.
Oracle TNS listener (´ë°³´Â Æ÷Æ® 1521À» »ç¿ë)·Î Á¢¼ÓÇÏ¿© "(CONNECT_DATA=(COMMAND=SERVICE_CURLOAD))" ¸í·ÉÀ» ÁÖ¸é Oracle ¼­¹ö´Â ¼º°øÀûÀÎ ½ÇÇàÀ» ¾Ë¸®´Â ¸Þ½ÃÁö·Î ÀÀ´äÇÑ´Ù. ±×·¯³ª, ÀÏ´Ü È£ÃâÀÚ°¡ Á¢¼ÓÀ» Á¾·áÇϸé Listener ¼­ºñ½º´Â ¹ÝÀÀÀ» ÇÏÁö ¾Ê´Â´Ù. ÀÌ·¯ÇÑ ¼­ºñ½º°ÅºÎ È¿°ú´Â ¾ó¸¶³ª ¿À·¡ °ø°ÝÀÚ°¡ ¿ø·¡ÀÇ Á¢¼ÓÀÌ ¿¬°áµÈ »óŸ¦ À¯ÁöÇÏ´À³Ä¿¡ µû¶ó ´Þ¶óÁø´Ù. ¸¸¾à È£ÃâÀÚ°¡ »õ·Î¿î Á¢¼ÓµéÀÌ ¼­ºñ½ºµÇ°í ÀÖÀ» µ¿¾È¿¡ Listener Á¢¼ÓÀ» ¿¬°áÇÑ »óŸ¦ À¯ÁöÇÑ´Ù¸é, ±× Listener ¼­ºñ½º´Â Access Violation(¸Þ¸ð¸® ÂüÁ¶ ¿¡·¯)°ú ÇÔ²² Crash°¡ ³ª°Å³ª DisableµÉ °ÍÀÌ´Ù. ¸¸¾à È£ÃâÀÚ°¡ ´Ù¸¥ ¿äûµéÀÌ ¼­ºñ½ºµÇ±â Àü¿¡ Listener Á¢¼ÓÀ» Á¾·áÇÑ´Ù¸é Listener ¼­ºñ½º´Â »õ·Î¿î Á¢¼Óµé¿¡ ´ëÇÑ ¼ö¿ëÀ» °ÅºÎÇÒ °ÍÀÌ´Ù.

¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ´ÜÁö TNS ListenerÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. ±×·¡¼­ Á¡°Ë°á°ú°¡ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)¸¦ º¸ÀÏ ¼ö ÀÖ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
Oracle 9i Release 2 (9.2.x)
Oracle 9i Release 1 (9.0.x)
Oracle 8i (8.1.x)

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/5678
http://www.rapid7.com/advisories/R7-0006.txt
ÇØ°áÃ¥ º¥´õ Á¦°ø ÆÐÄ¡µéÀ» ´Ù¿î·Îµå¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ ÆÐÄ¡Á¤º¸´Â ´ÙÀ½ Oracle Security Alert #42¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.oracle.com/technetwork/topics/security/2002alert42rev1-128177.pdf
°ü·Ã URL CVE-2002-1118 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)