[º¸¾È´º½º ±è°æ¾Ö] ¹Ì±¹ º¸¾Èȸ»ç Äþ¸®½º»çÀÇ ¸®´ª½º GNU C ¶óÀ̺귯¸®(glibc)¿¡¼ ¿ø°ÝÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2015-0235)ÀÌ ¹ß°ßµÅ ÀÌ¿ëÀÚµéÀÇ ÁÖÀÇ¿Í ÇÔ²² º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¿ä±¸µÈ´Ù.
CVE-2015-0235´Â ¸®´ª½º ¸í·É¾îÀÎ gethostbyname ÇÔ¼ö¿¡¼ ¹ß»ýÇÏ´Â ¹öÆÛ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ´Ù.
µû¶ó¼ ³·Àº ¹öÀü »ç¿ëÀÚ´Â ¾Ç¼ºÄÚµå °¨¿°¿¡ Ãë¾àÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÇØ°á¹æ¾È¿¡ µû¶ó ÃֽŹöÀüÀ¸·Î ¾÷µ¥ÀÌÆ®ÇØ¾ß ÇÑ´Ù.
¿µÇâÀ» ¹Þ´Â ÇØ´ç ½Ã½ºÅÛÀº GNU glibc 2.18 ÀÌÀü ¹öÀüÀ» »ç¿ëÇÏ´Â ½Ã½ºÅÛÀ̸ç, ÇØ°á ¹æ¾ÈÀº ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®°¡ °ø°³µÈ OS¸¦ ¿î¿µÇÏ°í ÀÖÀ» °æ¿ì, Âü°í»çÀÌÆ®ÀÇ ³»¿ëÀ» ÂüÁ¶ÇØ º¸¾È¾÷µ¥ÀÌÆ®¸¦ ¼öÇàÇØ¾ß ÇÑ´Ù.
- CentOS [1]
- Debian [2]
- Redhat [3]
- Ubuntu [4]
[Âü°í»çÀÌÆ®]
[1] http://lists.centos.org/pipermail/centos/2015-January/149413.html
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776391
[3] https://access.redhat.com/articles/1332213
[4] http://www.ubuntu.com/usn/usn-2485-1/
Á»´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ È¨ÆäÀÌÁö¸¦ È®ÀÎÇϰųª ±¹¹ø¾øÀÌ 118À» ÅëÇØ ¹®ÀÇÇÒ ¼ö ÀÖ´Ù.
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>