|
 |
[ °ø Áö ] BIND DNS ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2013-06-07 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
BIND DNS ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
°³¿ä
•ISC´Â BIND DNS¿¡¼ ¹ß»ýÇÏ´Â ¼ºñ½º °ÅºÎ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥ [1]
•´Ù¼öÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ´ÙÀ½°ú °°Àº ¼ºñ½º °ÅºÎ »óŰ¡ ¹ß»ýÇÒ ¼ö ÀÖÀ½
◦¿ø°ÝÀÇ »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ recursive query¸¦ ÇÒ °æ¿ì ¹ß»ýÇÒ ¼ö ÀÖ´Â ¼ºñ½º°ÅºÎ
Ãë¾àÁ¡ [CVE-2013-3919]
[ÇØ´ç ½Ã½ºÅÛ]
•¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
◦BIND 9.6-ESV-R9
◦BIND 9.8.5
◦BIND 9.9.3
•¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
◦BIND 9.6.0 ~ BIND 9.6-ESV-R8 ¹öÀü
◦BIND 9.8.0 ~ BIND 9.8.4-P2 ¹öÀü
◦BIND 9.9.0 ~ BIND 9.9.2-P2 ¹öÀü
ÇØ°á¹æ¾È
•Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ´Â BIND¹öÀüÀÇ °æ¿ì ¾Æ·¡ÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å[2]
◦BIND 9.9.3-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
◦BIND 9.8.5-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
◦BIND 9.6-ESV-R9-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
¿ë¾îÁ¤¸®
•BIND(Berkeley Internet Name Daemon) : ³×ÀÓ¼¹ö¸¦ ¿î¿µÇϱâ À§ÇÑ ¼¹öÃø ¼ÒÇÁÆ®¿þ¾î
±âŸ¹®ÀÇ»çÇ×
•Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://kb.isc.org/article/AA-00967
[2] http://ftp.isc.org/isc/bind9/
---------------------------------------------------------------------------
°¨»çÇÕ´Ï´Ù.
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|