|
 |
[ °ø Áö ] Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2018-03-19 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
¡à °³¿ä
o Samba ¼ÒÇÁÆ®¿þ¾î¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥
o ³·Àº ¹öÀü »ç¿ëÀÚ´Â ¼ºñ½º °ÅºÎ, ÆÐ½º¿öµå º¯°æ °ø°Ý¿¡ Ãë¾àÇϹǷÎ, ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í
¡à ¼³¸í
o RPC ½ºÇ® ¼ºñ½º°¡ ¿ÜºÎ µ¥¸óÀ¸·Î ½ÇÇàµÇµµ·Ï ±¸¼ºµÈ °æ¿ì, À̸¦ È£ÃâÇÏ´Â °úÁ¤¿¡¼ ÀÔ·Â °ª¿¡ ´ëÇÑ °ËÁõ ¹ÌÈíÀ¸·Î Àμâ
½ºÇ®·¯ ¼ºñ½º°¡ Áß´ÜµÉ ¼ö ÀÖ´Â ¼ºñ½º °ÅºÎ Ãë¾àÁ¡(CVE-2018-1050) [1]
o Samba4 Active Directory Domain ControllerÀÇ LDAP ¼¹ö¿¡¼ ±ÇÇÑ °ËÁõÀÌ ¹ÌÈíÇÏ¿© ´Ù¸¥ »ç¿ëÀÚÀÇ ºñ¹Ð¹øÈ£¸¦ º¯°æÇÒ
¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2018-1057) [2]
¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç°
o 4.7.5 ¹× ÀÌÀü ¹öÀü
o 4.6.13 ¹× ÀÌÀü ¹öÀü
o 4.5.15 ¹× ÀÌÀü ¹öÀü
o 4.4.x, 4.3.x, 4.2.x, 4.1.x, 4.0.x ¹öÀü
¡à ÇØ°á ¹æ¾È
o Samba 4.7.x ¹öÀü
- Samba 4.7.6 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [3]
o Samba 4.6.x ¹öÀü
- Samba 4.6.14 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [4]
o Samba 4.5.x ¹öÀü
- Samba 4.5.16 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [5]
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://www.samba.org/samba/security/CVE-2018-1050.html
[2] https://www.samba.org/samba/security/CVE-2018-1057.html
[3] https://www.samba.org/samba/history/samba-4.7.6.html
[4] https://www.samba.org/samba/history/samba-4.6.14.html
[5] https://www.samba.org/samba/history/samba-4.5.16.html
---------------------------------------------------------------------------
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|