English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28189
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç Windows È£½ºÆ®¿¡´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÑ Broadcom BCMWL5.SYS ¹«¼± µð¹ÙÀ̽º µå¶óÀ̹ö°¡ Á¸ÀçÇÑ´Ù. BCMWL5.SYS µå¶óÀ̹ö´Â 802.11 Probe(°Ëħ) ÀÀ´ä¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿©, ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Ãë¾àÇÑ È£½ºÆ®·Î ±ä SSID Çʵ带 Æ÷ÇÔÇÏ°í ÀÖ´Â Àß Á¶ÀÛµÈ 802.11 Probe(°Ëħ) ÀÀ´ä ÇÁ·¹ÀÓ(frame)À» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½ÃÅ°°Å³ª ¼­ºñ½º °ÅºÎ Á¶°ÇÀ» À¯¹ßÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://projects.info-pull.com/mokb/MOKB-11-11-2006.html
http://isotf.org/advisories/zert-01-111106.htm
http://isc.incidents.org/diary.php?storyid=1845
http://www.securiteam.com/mokb/projects.info-pull.com/mokb/MOKB-11-11-2006.html
http://www.kb.cert.org/vuls/id/209376
http://securitytracker.com/id?1017212
http://secunia.com/advisories/22831

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Broadcom Wireless Driver 3.50.21.10 ÀÌÇÏ ¹öÀüµé
Linksys WPC300N 4.100.15.5 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ LinksysÀÇ °æ¿ì:
´ÙÀ½ Linksys WPC300N À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ µå¶óÀ̹ö ¹öÀü(4.100.15.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù(Downloads¸¦ Ŭ¸¯ ÈÄ Version 1.0À» ¼±ÅÃ):
http://homesupport.cisco.com/en-apac/support/adapters/WPC300N/download

ZonetÀÇ °æ¿ì:
ZonetÀº ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¥´õ¿¡ ¹®ÀÇÇÏ¿© °¡Àå ÃÖ±ÙÀÇ µå¶óÀ̹ö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-5882 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 30202 (ISS)