[º¸¾È´º½º ±è°æ¾Ö ±âÀÚ] Dnsmasq ¼ÒÇÁÆ®¿þ¾î¿¡¼ ·£¼¶¿þ¾î °¨¿°À̳ª ¼¹ö ħÇØ µîÀÇ ÇÇÇØ°¡ ¹ß»ýÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ¹ß°ßµÆ´Ù.
À̹ø¿¡ ¹ß°ßµÈ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°´Ù.
¡â·ÎÄà ³×Æ®¿öÅ©¿¡¼ ÀͽºÇ÷ÎÀÕµÉ ¼ö ÀÖ´Â DNS Subsystem ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡(CVE-2017-14491) [1]
¡âIPv6 ¶ó¿ìÅÍÀÇ ¾Ë¸² ¿äû¿¡¼ ¿ø°Ý ÄÚµå ½ÇÇàÀ» °¡´ÉÇÏ°Ô ÇÏ´Â Èü ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2017-14492) [2]
¡âCVE-2017-14494 Ãë¾àÁ¡°ú ÇÔ²² »ç¿ëµÇ¾úÀ» ¶§ ¿ø°Ý ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ ½ºÅà ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2017-14493) [3]
¡âRelay·Î ±¸¼ºµÇ¾úÀ» ¶§ DHCPv6 ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¹ß»ýÇÏ´Â ¸Þ¸ð¸® Á¤º¸ ³ëÃâ Ãë¾àÁ¡(CVE-2017-14494) [4]
¡â–add-mac, add-cpe-id ¶Ç´Â -add-subnet ¿É¼ÇÀÌ ¼³Á¤µÈ dnsmasq¿¡¼ ¹ß»ýÇÏ´Â ¼ºñ½º °ÅºÎ °ø°ÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® Á¤º¸ ³ëÃâ Ãë¾àÁ¡(CVE-2017-14495) [5]
¡â–add-mac, add-cpe-id ¶Ç´Â -add-subnet ¿É¼ÇÀÌ ¼³Á¤µÈ dnsmasqÀÇ add_pseudoheader ÇÔ¼ö¿¡¼ ¹ß»ýÇÏ´Â ¼ºñ½º °ÅºÎ °ø°ÝÀÌ °¡´ÉÇÑ Á¤¼ö ¿À¹öÇ÷οì Ãë¾àÁ¡(CVE-2017-14496) [6]
¡âDNSÀÇ ÆÐŶ Å©±â°¡ ¼³Á¤µÈ Å©±âº¸´Ù Ŭ ¶§ ÇÁ·Î±×·¥ ½ÇÇàÀÌ Á¾·áµÇ´Â Ãë¾àÁ¡(CVE-2017-13704) [7]
ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â ¹öÀüÀº Dnsmasq 2.78 ÀÌÀü ¹öÀüÀ̸ç, ÇØ´ç ¹öÀü »ç¿ëÀÚ´Â Dnsmasq 2.78 ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® Àû¿ë[8]ÇØ¾ß ÇÑ´Ù.
Á»´õ ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ(±¹¹ø¾øÀÌ 118)¿¡ ¹®ÀÇÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
[1]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=62cb936cb7ad5f219715515ae7d32dd281a5aa1f
[2]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=24036ea507862c7b7898b68289c8130f85599c10
[3]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=3d4ff1ba8419546490b464418223132529514033
[4]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=33e3f1029c9ec6c63e430ff51063a6301d4b2262
[5]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=51eadb692a5123b9838e5a68ecace3ac579a3a45
[6]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=897c113fda0886a28a986cc6ba17bb93bd6cb1c7
[7]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=63437ffbb58837b214b4b92cb1c54bc5f3279928
[8]http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=summary
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>