[ °ø Áö ] Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í 2018-03-19

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------

¡à °³¿ä
o Samba ¼ÒÇÁÆ®¿þ¾î¿¡¼­ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥
o ³·Àº ¹öÀü »ç¿ëÀÚ´Â ¼­ºñ½º °ÅºÎ, ÆÐ½º¿öµå º¯°æ °ø°Ý¿¡ Ãë¾àÇϹǷÎ, ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í

¡à ¼³¸í
o RPC ½ºÇ® ¼­ºñ½º°¡ ¿ÜºÎ µ¥¸óÀ¸·Î ½ÇÇàµÇµµ·Ï ±¸¼ºµÈ °æ¿ì, À̸¦ È£ÃâÇÏ´Â °úÁ¤¿¡¼­ ÀÔ·Â °ª¿¡ ´ëÇÑ °ËÁõ ¹ÌÈíÀ¸·Î Àμâ

   ½ºÇ®·¯ ¼­ºñ½º°¡ Áß´ÜµÉ ¼ö ÀÖ´Â ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡(CVE-2018-1050) [1]
o Samba4 Active Directory Domain ControllerÀÇ LDAP ¼­¹ö¿¡¼­ ±ÇÇÑ °ËÁõÀÌ ¹ÌÈíÇÏ¿© ´Ù¸¥ »ç¿ëÀÚÀÇ ºñ¹Ð¹øÈ£¸¦ º¯°æÇÒ

   ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2018-1057) [2]
  
¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç°
o 4.7.5 ¹× ÀÌÀü ¹öÀü
o 4.6.13 ¹× ÀÌÀü ¹öÀü
o 4.5.15 ¹× ÀÌÀü ¹öÀü
o 4.4.x, 4.3.x, 4.2.x, 4.1.x, 4.0.x ¹öÀü

¡à ÇØ°á ¹æ¾È
o Samba 4.7.x ¹öÀü
   - Samba 4.7.6 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [3]
  o Samba 4.6.x ¹öÀü
   - Samba 4.6.14 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [4]
  o Samba 4.5.x ¹öÀü
   - Samba 4.5.16 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë [5]
  
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118

[Âü°í»çÀÌÆ®]
  [1] https://www.samba.org/samba/security/CVE-2018-1050.html
  [2] https://www.samba.org/samba/security/CVE-2018-1057.html
  [3] https://www.samba.org/samba/history/samba-4.7.6.html
  [4] https://www.samba.org/samba/history/samba-4.6.14.html
  [5] https://www.samba.org/samba/history/samba-4.5.16.html
  


---------------------------------------------------------------------------

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]