[º¸¾È´º½º ±Ç ÁØ] ¿À¶óŬ »ç´Â Oracle µ¥ÀÌÅͺ£À̽ºÀÇ TNS listener Ãë¾àÁ¡¿¡ ´ëÇÑ ÀÓ½ÃÁ¶Ä¡ ±Ç°í»çÇ×À» ¹ßÇ¥Çß´Ù.
ÀÌ´Â 4¿ù¿¡ ¹ßÇ¥µÈ Critical Patch Update¸¦ ÅëÇØ ÆÐÄ¡µÇÁö ¾ÊÀº Ãë¾àÁ¡¿¡ ´ëÇÑ PoC(°³³äÁõ¸í) Äڵ尡 °ø°³µÈ °Í°ú °ü·Ã ÆÐÄ¡ Àü¿¡ ÃëÇÒ ¼ö ÀÖ´Â Á¶Ä¡¿¡ ´ëÇØ º¸¾È±Ç°í¸¦ ÇÑ °ÍÀÌ´Ù(º»Áö 5¿ù 2ÀÏÀÚ ±â»ç, ¿À¶óŬ Ãë¾àÁ¡ PoC ÄÚµå °ø°³...¡°¾î¶ó! ÆÐÄ¡°¡ ¾ÈµÆ³×?¡± ÂüÁ¶).
TNS listener¿Í °ü·ÃµÈ Ãë¾àÁ¡Àº ¿ø°Ý¿¡¼ »ç¿ëÀÚ ÀÎÁõ ¾øÀÌ µ¥ÀÌÅͺ£À̽º·ÎÀÇ ¿¬°áÀ» ¿³º¸°Å³ª ÀÓÀÇÀÇ ¸í·É¾î ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡À¸·Î, ÇØ´çµÇ´Â ¼ÒÇÁÆ®¿þ¾î´Â Oracle Database 11g Release 2, versions 11.2.0.2, 11.2.0.3/ Oracle Database 11g Release 1, version 11.1.0.7/ Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5ÀÌ´Ù.
ÀÓ½ÃÁ¶Ä¡·Î´Â RAC(Real Application Clusters) »ç¿ëÀÚÀÇ °æ¿ì My Oracle Support Note 1340831.1À» Âü°í[2]ÇÏ°í, RAC ºñ»ç¿ëÀÚÀÇ °æ¿ì´Â My Oracle Support Note 1453883.1 Âü°í[3]ÇÑ ÈÄ, º¥´õ»ç ¹× À¯Áöº¸¼ö¾÷ü¿Í ÇùÀÇ¡¤°ËÅäÇؼ Á¶Ä¡¸¦ ÃëÇÒ °ÍÀ» KISA ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ ÃøÀº ´çºÎÇß´Ù.
[Âü°í»çÀÌÆ®]
[1]http://www.oracle.com/technetwork/topics/security/alert-cve
-2012-1675-1608180.html
[2] https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1340831.1
[3] https://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=1453883.1
*TNS(Transparent Network Substrate) : Oracle¿¡¼ °³¹ßÇÑ ±â¼ú·Î ¼·Î ´Ù¸¥ Network ±¸¼ºÀ» °¡Áö°í ÀÖ´Â Client/Server ¶Ç´Â Server/Server °£¿¡µµ µ¥ÀÌÅÍ Àü¼ÛÀ» °¡´ÉÇÏ°Ô ÇØÁÖ´Â ³×Æ®¿öÅ© ±â¼ú
*RAC(Real Application Clusters) : Oracle µ¥ÀÌÅͺ£À̽º ȯ°æ¿¡¼ Ŭ·¯½ºÅ͸µ°ú °í°¡¿ë¼º ±â´ÉÀ» °¡´ÉÄÉ ÇÏ´Â Ãß°¡ ±â´É
[±Ç ÁØ ±âÀÚ(editor@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>