ShellShock(CVE-2014-6271) ์ทจ์•ฝ์ 

๊ฐœ์š” 2014๋…„ 9์›” ์œ ๋‹‰์Šค(UNIX) ์šด์˜์ฒด์ œ์˜ Bash Shell์—์„œ ๋ฐœ์ƒํ•œ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. ๊ฐ™์€ ํ•ด์— OpenSSL์˜ ๋ฌธ์ œ๋กœ ๋ฐœ์ƒํ•œ Heartbleed ๋ณด๋‹ค ํŒŒ๊ธ‰ํšจ๊ณผ๊ฐ€ ๋”์šฑ ์ปธ๋˜ ์‚ฌ๊ฑด์ด์—ˆ์Šต๋‹ˆ๋‹ค. ์‰˜ ์‡ผํฌ์˜ ๊ฒฝ์šฐ UNIX ์ด์™ธ์—๋„ MAC OSX, Android, OpenBSD, DHCP Client, CGI๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์›น์„œ๋ฒ„ ๋“ฑ ํ•ด๋‹น ์šด์˜์ฒด์ œ์— ์ทจ์•ฝํ•œ Bash Shell์„ ์‚ฌ์šฉํ•˜๋Š” ๋ชจ๋“  ์šด์˜์ฒด์ œ์—์„œ ๋ฐœ์ƒํ•˜์˜€์œผ๋ฉฐ ๋ฌด์—‡๋ณด๋‹ค ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ root ๊ถŒํ•œ์„ ํš๋“ํ•˜๊ฑฐ๋‚˜ ๋Œ€์ƒ ์„œ๋ฒ„์— ์ง์ ‘ ๋ช…๋ น์„ ๋‚ด๋ฆฌ๋Š” ๋ฐฉ๋ฒ•๋„ ๊ฐ€๋Šฅํ–ˆ์Šต๋‹ˆ๋‹ค. ์ทจ์•ฝํ•œ ๋ฒ„์ „ GNU Bash 4.3์„ ํฌํ•จํ•˜์—ฌ ์ด์ „ ๋ชจ๋‘ bash-3.0-27.el4.2 bash-3.2-32.el5_9.2 bash-3.2-32.el5_9.1 bash-3.2-24..

WEB