[ °ø Áö ] BIND DNS ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í 2013-06-07

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

BIND DNS ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------

°³¿ä

•ISC´Â BIND DNS¿¡¼­ ¹ß»ýÇÏ´Â ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥ [1]
•´Ù¼öÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ´ÙÀ½°ú °°Àº ¼­ºñ½º °ÅºÎ »óŰ¡ ¹ß»ýÇÒ ¼ö ÀÖÀ½
◦¿ø°ÝÀÇ »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛµÈ recursive query¸¦ ÇÒ °æ¿ì ¹ß»ýÇÒ ¼ö ÀÖ´Â ¼­ºñ½º°ÅºÎ
Ãë¾àÁ¡ [CVE-2013-3919]

[ÇØ´ç ½Ã½ºÅÛ]

•¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
◦BIND 9.6-ESV-R9
◦BIND 9.8.5
◦BIND 9.9.3  
•¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î
◦BIND 9.6.0 ~ BIND 9.6-ESV-R8 ¹öÀü
◦BIND 9.8.0 ~ BIND 9.8.4-P2 ¹öÀü
◦BIND 9.9.0 ~ BIND 9.9.2-P2 ¹öÀü
ÇØ°á¹æ¾È

•Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ´Â BIND¹öÀüÀÇ °æ¿ì ¾Æ·¡ÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å[2]
◦BIND 9.9.3-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
◦BIND 9.8.5-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
◦BIND 9.6-ESV-R9-P1 ¹öÀüÀ¸·Î ¾÷±×·¹ÀÌµå ±Ç°í
¿ë¾îÁ¤¸®

•BIND(Berkeley Internet Name Daemon) : ³×ÀÓ¼­¹ö¸¦ ¿î¿µÇϱâ À§ÇÑ ¼­¹öÃø ¼ÒÇÁÆ®¿þ¾î


±âŸ¹®ÀÇ»çÇ×

•Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://kb.isc.org/article/AA-00967
[2] http://ftp.isc.org/isc/bind9/

---------------------------------------------------------------------------

°¨»çÇÕ´Ï´Ù.

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]