|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
¿Ã·ÁÁü: 2015.1.28 ¼ö, 2:02 pm ÁÖÁ¦: ¸®´ª½º glibc Ãë¾àÁ¡, "GHOST" |
|
|
glibc¿¡ Àϸí "GHOST"¶ó°í ºÒ¸®´Â ½É°¢ÇÑ Ãë¾àÁ¡(CVE-2015-0235)ÀÌ ¹ß°ßµÇ¾ú´Ù. gblic 2.17ÀÌÇÏ(2013.5.21 ÀÌÀü ¹öÀü)´Â gethostbyname(), gethostbyname2() ÄÝÀÇ ¹ö±×·Î ·ÎÄðú ¿ø°ÝÁö¿¡¼ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù. Exim ¸ÞÀϼ¹ö´Â À©°ÝÁö¿¡¼ Ãë¾àÇÑ °ÍÀ¸·Î È®ÀεǾú°í, gethostbyname ÄÝÀ» »ç¿ëÇÏ´Â ¿©·¯ µ¥¸óµéÀÌ ¹®Á¦°¡ ÀÖÀ» ¼ö ÀÖ´Ù.
* Linux "GHOST" Vulnerability Hits Glibc Systems
http://www.phoronix.com/scan.php?page=news_item&px=Linux-GHOST-Glibc-Security
* GHOST: glibc gethostbyname buffer overflow
http://www.openwall.com/lists/oss-security/2015/01/27/9
Àοë: | we discovered that it was fixed on May 21, 2013 (between the releases of glibc-2.17 and glibc-2.18 ).
Unfortunately, it was not recognized as a security threat; as a result, most stable and long-term-support distributions were left exposed (and still are):
Debian 7 (wheezy), Red Hat Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04, for example.
|
´ÙÇàÀÎ °ÍÀº apache, nginx, lighttpd µî ´ëÇ¥ÀûÀÎ À¥¼¹ö¿Í proftpd, vsftpd, pure-ftpd µî ´Ù¼ö FTP ¼¹ö, openssh´Â Ãë¾àÇÏÁö ¾Ê´Â °ÍÀ¸·Î ¹àÇôÁ³´Ù.
Qualys Security Advisory teamÀÌ OSS Security ¸ÞÀϸµ¸®½ºÆ®¿¡ º¸³½ ³»¿ë¿¡ µû¸£¸é, ´ÙÀ½ µ¥¸óµéÀº ¹®Á¦ ¾ø´Ù°í ÇÑ´Ù.
http://www.openwall.com/lists/oss-security/2015/01/27/18
Àοë: |
apache, cups, dovecot, gnupg, isc-dhcp, lighttpd, mariadb/mysql, nfs-utils, nginx, nodejs, openldap, openssh, postfix, proftpd, pure-ftpd, rsyslog, samba, sendmail, sysklogd, syslog-ng, tcp_wrappers, vsftpd, xinetd.
|
RHEL(CentOS)Àº ÆÐÄ¡¸¦ Á¦°øÇÏ°í ÀÖ´Ù.
* RHEL5, CentOS 5 (ÆÐÄ¡µÈ ÆÐÅ°Áö¸í : glibc-2.5-123.el5_11.1)
https://rhn.redhat.com/errata/RHSA-2015-0090.html
* RHEL6 & 7, CentOS 6 & 7 (RHEL6 ÆÐÄ¡µÈ ÆÐÅ°Áö¸í : glibc-2.12-1.149.el6_6.5, RHEL 7 : glibc-2.17-55.el7_0.5)
https://rhn.redhat.com/errata/RHSA-2015-0092.html
ÄÚµå: |
# yum -y update ( -y´Â ¾÷µ¥ÀÌÆ® ÇÒ °ÍÀÎÁö ¹¯Áö ¾Ê°í ¹Ù·Î update)
... »ý·« ...
glibc x86_64 2.12-1.149.el6_6.5 updates 3.8 M
glibc-common x86_64 2.12-1.149.el6_6.5 updates 14 M
glibc-devel x86_64 2.12-1.149.el6_6.5 updates 983 k
glibc-headers x86_64 2.12-1.149.el6_6.5 updates 612 k
|
|
|
À§·Î |
|
|
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
|
À§·Î |
|
|
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|