|
 |
[ °ø Áö ] OpenSSH Client º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2016-01-15 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
OpenSSH Client º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
¡à °³¿ä
o OpenSSH Client¿¡¼ ¸Þ¸ð¸® Á¤º¸ ³ëÃâ Ãë¾àÁ¡ µî 2°³ÀÇ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥[1]
¡à ¼³¸í
o roamin_common.c ¾ÈÀÇ resend_bytes ÇÔ¼ö¿¡¼ ¸Þ¸ð¸® Á¤º¸ ³ëÃâ(Information leak) Ãë¾àÁ¡(CVE-2016-0777)[2]
o roamin_common.c ¾ÈÀÇ roamin_read ÇÔ¼ö¿Í roaming_write ÇÔ¼ö¿¡¼ Èü ¹öÆÛ¿À¹öÇ÷οì(heap-based buffer overflow)°¡ ¹ß»ý (CVE-2016-0778)[3]
¡à ¿µÇâ¹Þ´Â ¹öÀü
o OpneSSH 5.x, 6.x, 7.x ~ 7.1p1
¡à ÇØ°á ¹æ¾È
o OpneSSH 7.1p2 ·Î ¾÷µ¥ÀÌÆ®
o Roming ±â´ÉÀ» ºñȰ¼ºÈ
- ¸®´ª½º ¹× FreeBSD
echo 'UseRoaming no' | sudo tee -a /etc/ssh/ssh_config
- Mac OSX
echo "UseRoaming no" >> ~/.ssh/config
¡à ¿ë¾î ¼³¸í
o ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow) : ƯÁ¤ ÇÁ·Î±×·¥¿¡ ÇÒ´çµÈ ¸Þ¸ð¸® ¿µ¿ªÀ» ÃʰúÇÏ´Â Å©±âÀÇ µ¥ÀÌÅ͸¦ ÀԷ½ÃÅ´À¸·Î½á ¹ß»ýÇÏ´Â Ãë¾àÁ¡
¡à ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø ¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] http://www.openssh.com/txt/release-7.1p2
[2] https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0777
[3] https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0778
°¨»çÇÕ´Ï´Ù.
---------------------------------------------------------------------------
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|