CVE-2016-2114, CVE-2016-2115
1. CVE-2016-2111
Samba 3.x¿Í, 4.2.11 ÀÌÀüÀÇ 4.x ¹öÀü, 4.3.8 ÀÌÀüÀÇ 4.3.x ¹öÀü, 4.4.2 ÀÌÀüÀÇ 4.4.x ¹öÀüÀÇ NETLOGON ¼ºñ½ºÀÇ Ãë¾àÁ¡À¸·Î µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¸¦ ¼³Á¤ÇÒ ¶§ ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ ÄÄÇ»ÅÍ À̸§À» ½ºÇªÇÎÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ·Î½á ¹Î°¨ÇÑ Á¤º¸ÀÇ Å»Ãë°¡ °¡´ÉÇØÁø´Ù. CVE-2015-0005¿Í °ü·ÃÀÌ ÀÖ´Â Ãë¾àÁ¡ÀÌ´Ù.
2. CVE-2016-2112
Samba 3.x ¹öÀü, 4.2.11 ÀÌÀüÀÇ 4.x ¹öÀü, 4.3.8 ÀÌÀüÀÇ 4.3.x ¹öÀü, 4.4.2 ÀÌÀüÀÇ 4.4.x ¹öÀü¿¡ ÀÖ´Â LDAP Ŭ¶óÀ̾ðÆ® ¶óÀ̺귯¸®ÀÇ Ãë¾àÁ¡À¸·Î client ldap sasl wrapping ¼¼ÆÃÀ» ÀνÄÇÏÁö ¸øÇÑ´Ù. À̷νá Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇØÁø´Ù.
3. CVE-2016-2113
Samba 4.2.11 ÀÌÀü 4.x ¹öÀü, 4.3.8 ÀÌÀüÀÇ 4.3.x ¹öÀü, 4.4.2 ÀÌÀüÀÇ 4.4.x ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î TSL ¼¹ö·ÎºÎÅÍ ¿Â X.509 ÀÎÁõ¼¸¦ Á¦´ë·Î È®ÀÎÇÏÁö ¾Ê´Â´Ù. À̷νá Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇØÁö°í, ¹Î°¨ÇÑ Á¤º¸¿¡ ´ëÇÑ ¸®½ºÅ©°¡ ¹ß»ýÇÑ´Ù.
4. CVE-2016-2114
Samba 4.2.11 ÀÌÀüÀÇ 4.x ¹öÀü, 4.3.8 ÀÌÀüÀÇ 4.2.11 ¹öÀü, 4.4.2 ÀÌÀüÀÇ 4.4.x ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î server signing = mandatory ¶ó´Â ¼¼ÆÃÀ» Á¦´ë·Î ÀоîµéÀÌÁö ¸øÇÑ´Ù. À̷νá Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇØÁø´Ù.
5. CVE-2016-2115
Samba 3.x ¹öÀü, 4.2.11 ÀÌÀüÀÇ 4.x ¹öÀü, 4.3.8 ÀÌÀüÀÇ 4.3.x ¹öÀü, 4.4.2 ÀÌÀüÀÇ 4.4.x ¹öÀü¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î DCERPC ¼¼¼Ç ³» SMB ¼¸íÀ» ¿ä±¸ÇÏÁö ¾Ê´Â´Ù. À̷νá Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇØÁø´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>