[ °ø Áö ] Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í 2018-08-17

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

Samba Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------

¡à °³¿ä
o Samba ¼ÒÇÁÆ®¿þ¾î¿¡¼­ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥[1]
  o ³·Àº ¹öÀü »ç¿ëÀÚ´Â Á¤º¸³ëÃâ ¹× ¼­ºñ½º°ÅºÎ °ø°Ý µî¿¡ Ãë¾àÇϹǷÎ, ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ±Ç°í

¡à ¼³¸í
o Samba 4.7.0 ÀÌ»ó ¹öÀü¿¡¼­ ÄÚµå À籸¼ºÀ¸·Î ÀÎÇØ Ãë¾àÇÑ ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ¿© ¹ß»ýÇÏ´Â º¸¾È±â´É ¿ìȸ Ãë¾àÁ¡(CVE-2018-1139) [2]
  o ÀÔ·ÂµÈ ¸Å°³ º¯¼ö¿¡ ´ëÇÑ °ËÁõÀÌ ´©¶ôµÇ¾î LDAP ¹× DNS ¼­¹ö°¡ Ãæµ¹ÇÏ´Â ¼­ºñ½º°ÅºÎ Ãë¾àÁ¡(CVE-2018-1140) [3]
  o libsmbclient¿¡¼­ °ø°Ý¼­¹ö°¡ Ŭ¶óÀ̾ðÆ®ÀÇ Èü ¸Þ¸ð¸®¸¦ µ¤¾î¾º¿ì´Â °ÍÀ» Çã¿ëÇÏ¿© ¹ß»ýÇÏ´Â ¹öÆÛ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2018-10858) [4]
   ¡Ø libsmbclient : ÀÀ¿ëÇÁ·Î±×·¥ÀÌ ³×Æ®¿öÅ© ¸®¼Ò½º¸¦ ¼³Á¤ÇÒ ¼ö ÀÖµµ·Ï ÇÏ´Â ¶óÀ̺귯¸® µµ±¸ ¼¼Æ®
o Samba°¡ Active Directory Domain ControllerÀÏ ¶§, ³ÎÆ÷ÀÎÅÍ ¿ªÂüÁ¶·Î Samba ÇÁ·Î¼¼½º°¡ ÁߴܵǴ ¼­ºñ½º°ÅºÎ Ãë¾àÁ¡(CVE-2018-10918) [5]
  o °Ë»ö½ÄÀ» ÀÌ¿ëÇÏ¿© LDAP °³Ã¼¿Í ÀÏÄ¡/ºÒÀÏÄ¡ÇÏ´Â °á°ú°ª ¹ÝȯÀ» ÅëÇØ ±â¹ÐÁ¤º¸°¡ ³ëÃâµÇ´Â Á¤º¸³ëÃâ Ãë¾àÁ¡(CVE-2018-10919) [6]

¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç°
o CVE-2018-1139, 10918
   - 4.7, 4.7.3, 4.7.6, 4.8, 4.8.1, 4.8.2, 4.8.3
  o CVE-2018-1140
   - 4.8, 4.8.1, 4.8.2, 4.8.3
  o CVE-2018-10858
   - ¿µÇâ ¹Þ´Â ¹öÀü È®ÀÎ(https://www.securityfocus.com/bid/105085)
  o CVE-2018-10919
   - ¿µÇâ ¹Þ´Â ¹öÀü È®ÀÎ(https://www.securityfocus.com/bid/105081)
  
¡à ÇØ°á ¹æ¾È
o ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î ¹öÀü »ç¿ëÀÚ´Â ¾÷µ¥ÀÌÆ® ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ¼öÇà [1]
   ¡Ø ÅëÇÕ ¾÷µ¥ÀÌÆ® ¹öÀü : Samba 4.8.4

¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118

[Âü°í»çÀÌÆ®]
[1] https://www.samba.org/samba/history/security.html
[2] https://www.samba.org/samba/security/CVE-2018-1139.html
[3] https://www.samba.org/samba/security/CVE-2018-1140.html
[4] https://www.samba.org/samba/security/CVE-2018-10858.html
[5] https://www.samba.org/samba/security/CVE-2018-10918.html
[6] https://www.samba.org/samba/security/CVE-2018-10919.html
  

---------------------------------------------------------------------------

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]