±â¼ú ÀÚ·á½Ç

°Ô½Ã±Û º¸±â
[Linux] OpenSSH CVE-2023-38408 º¸¾È Ãë¾àÁ¡ Á¶Ä¡
Date : 2023-12-26
Name : ¼­¹ö¸ó
Hits : 295

 

¾È³çÇϼ¼¿ä. ÁÖ½Äȸ»ç ¼­¹ö¸ó ÀÔ´Ï´Ù.

±Ý¹ø Æ÷½ºÆÿ¡¼­´Â OpenSSH  CVE (Common Vulnerabilities and Exposures) Áï ¾Ë·ÁÁø º¸¾È¹®Á¦¿¡

´ëÇÑ ºÐ¼®°ú Á¶Ä¡ ¹æ¹ý¿¡ ´ëÇؼ­ ¾Ë¾Æº¸µµ·Ï ÇÏ°Ú½À´Ï´Ù.

 

 

CVE ¶õ?

 

CVE(Common Vulnerabilities and Exposures)´Â °ø°³ÀûÀ¸·Î ¾Ë·ÁÁø ÄÄÇ»ÅÍ º¸¾È °áÇÔ ¸ñ·ÏÀÔ´Ï´Ù.

CVE´Â º¸Åë CVE ID ¹øÈ£°¡ ÇÒ´çµÈ º¸¾È °áÇÔÀ» ¶æÇÕ´Ï´Ù.

CVE´Â "Common Vulnerabilities and Exposures"ÀÇ ¾àÀÚ·Î, ÄÄÇ»ÅÍ ½Ã½ºÅÛ ¹× ¼ÒÇÁÆ®¿þ¾î¿¡¼­ ¹ß°ßµÈ º¸¾È Ãë¾àÁ¡µéÀ» ½Äº°ÇÏ°í ÃßÀûÇϱâ À§ÇÑ ±¹Á¦ÀûÀÎ ½Äº°Ã¼°èÀÔ´Ï´Ù.

ÀÌ ½Ã½ºÅÛÀº °¢°¢ÀÇ º¸¾È Ãë¾àÁ¡¿¡ ´ëÇØ °íÀ¯ÇÑ ½Äº°¹øÈ£(CVE ID)¸¦ ºÎ¿©ÇÏ¿© À̸¦ ÃßÀûÇÏ°í ±â·ÏÇÔÀ¸·Î½á, º¸¾È Àü¹®°¡µéÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ Á¤º¸¸¦ °øÀ¯ÇÏ°í, ÇØ´ç Ãë¾àÁ¡À» ÆľÇÇÏ°í ´ëÀÀÇÏ´Â µ¥ µµ¿òÀ» ÁÝ´Ï´Ù.

CVE ID´Â "CVE-YYYY-NNNN" Çü½ÄÀ» °¡Áö¸ç, YYYY´Â ÇØ´ç Ãë¾àÁ¡ÀÌ ¹ß°ßµÈ ¿¬µµ¸¦, NNNNÀº ÀϷùøÈ£¸¦ ³ªÅ¸³À´Ï´Ù. ¿¹¸¦ µé¾î, "CVE-2023-38408"Àº 2023³â¿¡ ¹ß°ßµÈ ƯÁ¤ º¸¾È Ãë¾àÁ¡À» ½Äº°ÇÏ´Â ¹øÈ£ÀÏ ¼ö ÀÖ½À´Ï´Ù.

º¸Åë CVE´Â º¸¾È ¾÷µ¥ÀÌÆ®, ÆÐÄ¡, ¶Ç´Â ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ Á¤º¸¸¦ °øÀ¯ÇÏ´Â µ¥ »ç¿ëµË´Ï´Ù. À̸¦ ÅëÇØ ¼ÒÇÁÆ®¿þ¾î Á¦Á¶»ç, º¸¾È ¿¬±¸ÀÚ, ½Ã½ºÅÛ °ü¸®ÀÚ µîÀÌ Ãë¾àÁ¡¿¡ ´ëÀÀÇÏ°í »ç¿ëÀÚµéÀ» º¸È£ÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù.

 

OpenSSH(CVE-2023-38408)

 

2023³â 7¿ù 19ÀÏ Redaht Àº OpenSSH °ü·Ã »õ·Î¿î Ãë¾àÁ¡À» ¹ß°ß ÇÏ¿´½À´Ï´Ù.

»ç¿ëÀÚ°¡ ÇØÄ¿¿¡°Ô °ø°Ý¹Þ¾Æ °¨¿µµÈ SSH ¼­¹ö¿¡ Ưº°ÇÑ ¹æ¹ýÀ» ÅëÇØ Á¢¼ÓÇÒ °æ¿ì ÇÇÇØ PC¿¡¼­

ÀÓÀÇÀÇ ¶óÀ̺귯¸®¸¦ È£ÃâÀÌ °¡´ÉÇÏ°í. ƯÁ¤ Á¶°Ç¿¡¼­´Â ÇÇÇØÀÚÀÇ PC¿¡¼­ ¿ø°Ý Äڵ带 ½ÇÇà ÇÒ ¼ö ÀÖ´Â

¹®Á¦Á¡À» È®ÀÎ ÇÏ¿´½À´Ï´Ù.

Ãâó : https://phoenix.security/openssh-agent-38408/

 

 

¿µÇâ ¹Þ´Â ½Ã½ºÅÛ

 

  • Redhat 6 Àüü
  • Redhat 7.9 ÀÌÇÏ
  • Redhat 8.7 ÀÌÇÏ
  • Redhat 9.0 ÀÌÇÏ
  • OpenSSH 9.1 ÀÌÇÏÀÇ ½Ã½ºÅÛ

 

´ëÀÀ¹æ¹ý

 

OpenSSH ÆÐÄ¡

 

CVE-2023-38408 Ãë¾àÁ¡ÀÌ ÆÐÄ¡µÈ ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ ÁøÇàÇÕ´Ï´Ù.

Redhat OS´Â ¾Æ·¡ ¹öÀü ÀÌ»óÀ¸·Î ¾÷µ¥ÀÌÆ®¸¦ ÁøÇàÇÕ´Ï´Ù.

#ÇöÀç ¹öÀü È®ÀÎ#
ssh -V
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022

#Redhat 7.X ´ëÀÀ¹öÀü#
openssh-7.4p1-23.el7_9

#Redhat 8.X ´ëÀÀ¹öÀü#
openssh-8.0p1-19.el8_8

#Redhat 9.X ´ëÀÀ¹öÀü#
openssh-8.7p1-11.el9_0

 

SSH Agent Forwarding -A ¿É¼Ç ºñÈ°¼ºÈ­

½Å·ÚÇÒ¼ö ¾ø´Â ¼­¹ö¿¡ SSH ¿¬°á½Ã -A ¿É¼ÇÀ» »ç¿ëÇÏÁö ¾Ê½À´Ï´Ù.

SSH Agent ForwardingÀº SSH Å° ¹× ÀÎÁõ¿¡ °ü·ÃµÈ ÇÁ·Î¼¼½º¸¦ ¾ÈÀüÇÏ°Ô Àü´ÞÇÏ´Â ±â´ÉÀÔ´Ï´Ù.

ÀϹÝÀûÀ¸·Î ¿ø°Ý ¼­¹ö¿¡ SSH·Î Á¢¼ÓÇÒ ¶§ ·ÎÄà ÄÄÇ»ÅÍÀÇ SSH Å°¸¦ »ç¿ëÇϴµ¥, Agent ForwardingÀ» »ç¿ëÇÏ¸é ·ÎÄà ÄÄÇ»ÅÍ¿¡ ÀÖ´Â SSH ¿¡ÀÌÀüÆ®¸¦ ÅëÇØ ¿ø°Ý ¼­¹ö·Î ÀÎÁõÀ» Àü´ÞÇÒ ¼ö ÀÖ½À´Ï´Ù.

Agent ForwardingÀÌ È°¼ºÈ­µÇ¸é ¿ø°Ý ¼­¹ö·Î Á¢¼ÓÇÑ ÈÄ¿¡µµ ·ÎÄà ÄÄÇ»ÅÍÀÇ SSH Å°¸¦ »ç¿ëÇÏ¿© ´Ù¸¥ ¼­¹ö¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ½À´Ï´Ù. À̸¦ ÅëÇØ Áß°£ ¼­¹ö¸¦ °ÅÄ¡Áö ¾Ê°íµµ ·ÎÄÿ¡¼­ ¿ø°Ý ¼­¹ö¸¦ ÅëÇØ ´Ù¸¥ ¼­¹ö·Î Á¢¼ÓÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù.

 
 
 
 
°¨»çÇÕ´Ï´Ù.

 

 

ÀÚ·á Âü°í :

https://access.redhat.com/security/cve/cve-2023-38408

https://www.cve.org/CVERecord?id=CVE-2023-38408

https://nvd.nist.gov/vuln/detail/CVE-2023-38408

https://knvd.krcert.or.kr/detailSecNo.do?IDX=5961

 

1u¼­¹ö / APC / DB / defog / DEFOG·¢ / dell5820 / dell5820t / dell7920 / dellpoweredge / dellr240 / dellr340 / dellr350 / dellr450 / dellr540 / dellr630 / dellr640 / dellr740 / dellr750 / dellserver / dellt40 / dellt440 / dellt5820 / dell¼­¹ö / DELL¼­¹öCPU / DELL¼­¹öRAIDÄÁÆ®·Ñ·¯ / DELL¼­¹öSASÇϵåµð½ºÅ© / DELL¼­¹ö°¡°Ýºñ±³ / DELL¼­¹ö°¡°Ýºñ±³°ßÀû / DELL¼­¹ö°ßÀû / DELL¼­¹ö±¸¸Å / DELL¼­¹öµð½ºÅ©±³Ã¼ / DELL¼­¹ö¸Þ¸ð¸® / DELL¼­¹öÆß¿þ¾î / DELL¼­¹öÇϵåµð½ºÅ©±¸¸Å / dell¿öÅ©½ºÅ×ÀÌ¼Ç / dl20 / dl20gen10 / dl360 / dl360gen10 / dl380 / dl380g10 / dl380gen10 / ECC¸Þ¸ð¸® / EDFOG·¢°¡°Ý / ESTSOFT / FIRMWARE / gpu¼­¹ö / gpuŸ¿öÇü¼­¹ö / HA¼Ö·ç¼Ç / hpdl20 / hpdl360 / hpdl360gen10 / hpdl380 / hpdl380g10 / HPE / HPE Service Pack for Proliant / HPE SPP / hpedl20 / hpedl20gen10 / hpedl360gen10 / hpe¼­¹ö / HPE¼­¹öCPU / HPE¼­¹öRAIDÄÁÆ®·Ñ·¯ / HPE¼­¹öSASÇϵåµð½ºÅ© / HPE¼­¹ö°¡°Ýºñ±³ / HPE¼­¹ö°¡°Ýºñ±³°ßÀû / HPE¼­¹ö°ßÀû / HPE¼­¹ö±¸¸Å / HPE¼­¹öµå¶óÀ̹ö¼³Ä¡ / HPE¼­¹öµð½ºÅ©±³Ã¼ / HPE¼­¹ö¸Þ¸ð¸® / HPE¼­¹öºñ¿ë / HPE¼­¹öÆß¿þ¾î / HPE¼­¹öÇϵåµð½ºÅ©±¸¸Å / hpgen10 / hpml30 / hpserver / hpz2 / hpz4 / hpz420 / hpz440 / hpz4g4 / hpz640 / hpz6g4 / hpz8g4 / hp¸¶ÀÌÅ©·Î¼­¹ö / hp¼­¹ö / hp¼­¹ö800 / hp¼­¹ö800w / hp¼­¹öcto / hp¼­¹öpc / HP¼­¹ö¸Þ¸ð¸® / hp¼­¹öÄÄÇ»ÅÍ / HP¼­¹öÆß¿þ¾î / HP¼­¹öÇϵåµð½ºÅ© / hp¿öÅ©½ºÅ×ÀÌ¼Ç / hpÇÁ·Î¶óÀ̾ðÆ® / HYPER BACKUP / ibm¼­¹ö / Intelligent Provisioning / KVM / KVM ±â¼úÁö¿øºñ(ºñ¿ë) / KVM ¼³Ä¡ºñ / L2½ºÀ§Ä¡ / L3½ºÀ§Ä¡ / LENONO¼­¹öSASÇϵåµð½ºÅ© / lenovop620 / lenovor650 / LENOVO¼­¹ö / LENOVO¼­¹öCPU / LENOVO¼­¹öRAIDÄÁÆ®·Ñ·¯ / LENOVO¼­¹ö°¡°Ýºñ±³ / LENOVO¼­¹ö°¡°Ýºñ±³°ßÀû / LENOVO¼­¹ö°ßÀû / LENOVO¼­¹ö±¸¸Å / LENOVO¼­¹öµð½ºÅ©±³Ã¼ / LENOVO¼­¹ö¸Þ¸ð¸® / LENOVO¼­¹öÇϵåµð½ºÅ©±¸¸Å / LENOVOÆß¿þ¾î¾÷µ¥ÀÌÆ® / Linux / ML30 / ml30gen10 / ML350GEN10 / ML360 / MSSQL / MSSQL ±â¼úÁö¿øºñ(ºñ¿ë) / MSSQL ¼³Ä¡ºñ / MYSQL / MySQL ±â¼úÁö¿øºñ(ºñ¿ë) / MySQL ¼³Ä¡ºñ / OS¼³Ä¡ / p17079-b21 / poweredger740 / poweredger750 / precision5820 / QUADRO / QUADRO±×·¡ÇÈÄ«µå / r240 / r340 / r440 / r740 / RHEL¼³Ä¡ / RMS·¢ / server / serverpc / SOPHOS / SPP / sr250 / sr650 / SYNOLOGY / SYNOLOGY³ª½º / UPS / UPS±â¼úÁö¿ø / UPS³³Ç° / UPS¼³Ä¡ / V3 / Windows¼­¹ö¼³Ä¡ / z420 / z620 / z840 / z8g4 / ±â¼úÁö¿øºñ(ºñ¿ë) / ³ª½º±â¼úÁö¿ø / ³ª½º¼³Ä¡Áö¿ø / ³×Æ®¿öÅ©½ºÀ§Ä¡ / ³×Æ®¿öÅ©Àåºñ / ´õºíÅ×ÀÌÅ© / µ¥ÀÌÅͺ£À̽º / µ¨5820 / µ¨¼­¹ö / µ¨¼­¹öºñ¿ë / µ¨¼­¹öÆß¿þ¾î¾÷µ¥ÀÌÆ® / µ¨¿öÅ©½ºÅ×ÀÌ¼Ç / µ¨ÄÄÇ»ÅÍ¿öÅ©½ºÅ×ÀÌ¼Ç / µðÆ÷±× / µðÆ÷±×·¢ / µðÆ÷±×·¢°¡°Ý / µö·¯´×pc / µö·¯´×¼­¹ö / ·¢ / ·¢(RACK) ±â¼úÁö¿øºñ(ºñ¿ë) / ·¢(RACK) ¼³Ä¡ºñ / ·¢³³Ç°¼³Ä¡ / ·¢¼³Ä¡ / ·¹³ë¹öp620 / ·¹³ë¹ö¼­¹ö / ·¹³ë¹ö¿öÅ©½ºÅ×ÀÌ¼Ç / ·¹³ëº¸¼­¹ö / ·¹³ëº¸¼­¹öÆß¿þ¾î / ·¹µåÇò¼³Ä¡ / ¸®´ª½º ±â¼úÁö¿øºñ(ºñ¿ë) / ¸®´ª½º ¼³Ä¡ºñ / ¸®´ª½º¼­¹ö / ¸®´ª½º¼­¹ö¼³Ä¡ / ¸®´ª½º¼­¹öÆ®·¯ºí½´Æà / ¸®´ª½ºÆ®·¯ºí½´Æà / ¸®¿í½º / ¹Ì´Ï¼­¹ö / ¹Ì´Ï¼­¹ö·¢ / ¹æÈ­º® / ¹æÈ­º® ±â¼úÁö¿øºñ(ºñ¿ë) / ¹æÈ­º® ¼³Ä¡ºñ / ¹æÈ­º®¿£Áö´Ï¾î / ¹é¾÷ / º¸¾È¼Ö·ç¼Ç / º¸¾È¼Ö·ç¼Ç±¸¸Å / º¸¾È¼Ö·ç¼Ç¼³Ä¡ / ¼­¹ö / ¼­¹ö ±â¼úÁö¿øºñ(ºñ¿ë) / ¼­¹ö ·¢¸¶¿îÆ®ºñ¿ë / ¼­¹ö ¼³Ä¡ºñ / ¼­¹ö Àå¾ÖÁ¶Ä¡ºñ¿ë / ¼­¹öCPU / ¼­¹öMEMORY / ¼­¹öOS¼³Ä¡ / ¼­¹öpc / ¼­¹ö°¡°Ý / ¼­¹ö±¸¸Å / ¼­¹ö±â¼úÁö¿ø / ¼­¹ö³³Ç° / ¼­¹öµð½ºÅ©Àå¾Öó¸® / ¼­¹ö·¢ / ¼­¹ö·º¸¶¿îÆ® / ¼­¹ö¸Þ¸ð¸® / ¼­¹ö¸ó / ¼­¹ö¸ó±â¼úÁö¿ø / ¼­¹ö¹é¾÷ / ¼­¹öº¸¾È / ¼­¹ö¿£Áö´Ï¾î / ¼­¹ö¿ëpc / ¼­¹ö¿ë±×·¡ÇÈÄ«µå / ¼­¹ö¿ë¸Þ¸ð¸® / ¼­¹ö¿ëÄÄÇ»ÅÍ / ¼­¹ö¿ëÇϵåµð½ºÅ© / ¼­¹öÄÄ / ¼­¹öÄÄÇ»ÅÍ / ¼­¹öÆ®·¯ºí½´Æà / ¼­¹öÈ£½ºÆà / ¼ÒÆ÷½º / ½ºÀ§Ä¡ / ½ºÀ§Ä¡ ±â¼úÁö¿øºñ(ºñ¿ë) / ½ºÀ§Ä¡ ¼³Ä¡ºñ / ½ºÅ丮Áö / ½ºÅ丮Áö ±â¼úÁö¿øºñ(ºñ¿ë) / ½ºÅ丮Áö ·¢¸¶¿îÆ®ºñ¿ë / ½ºÅ丮Áö ¼³Ä¡ºñ / ½ºÅ丮Áö Àå¾ÖÁ¶Ä¡ºñ¿ë / ½ºÅ丮Áö³³Ç°¼³Ä¡ / ½ºÅ丮Áö¼­¹ö / ½Ã³î·ÎÁöDS918 / ½Ã³î·ÎÁöHyperBackup / ½Ã³î·ÎÁö³ª½º / ½Ã³î·ÎÁö³ª½º¹é¾÷ / ½Ã³î·ÎÁöÇÏÀÌÆÛ¹é¾÷ / ½ÃÅ¥¾îµð½ºÅ© / ¾È·¦ / ¾Ë¾à / ¿Þµµ¿ì¼­¹ö¼³Ä¡ / ¿ìºÐÅõ¼³Ä¡ / ¿öÅ©½ºÅ×ÀÌ¼Ç / ¿öÅ©½ºÅ×À̼Çpc / ¿öÅ©½ºÅ×À̼ÇÄÄÇ»ÅÍ / À©µµ¿ì¼­¹ö / À©µµ¿ì¼­¹ö2016 / À©µµ¿ì¼­¹ö2019 / À©µµ¿ì¼­¹öÆ®·¯ºí½´Æà / À©µµ¿ìÁî ±â¼úÁö¿øºñ(ºñ¿ë) / À©µµ¿ìÁî ¼³Ä¡ºñ / À̽ºÆ®¼ÒÇÁÆ® / ÀÌÁßÈ­¼Ö·ç¼Ç / ÀÌÁßÈ­¼Ö·ç¼Ç±¸¸Å / ÀÌÁßÈ­¼Ö·ç¼Ç¼³Ä¡ / ÀÎÅͳݵð½ºÅ© / ÀÛ¾÷ÀåÄÄÇ»ÅÍ / Á¦¿Â¼­¹ö / Á¨¼­¹ö / Áß°í¼­¹ö / Áß°í¿öÅ©½ºÅ×ÀÌ¼Ç / Ä«º¸³ªÀÌÆ® / Ä«½ºÆÛ½ºÅ° / ÄÄÇ»Åͼ­¹ö / Äõµå·ÎP400 / Ÿ¿öÇü¼­¹ö / Æäµµ¶ó¼³Ä¡ / ÇÁ·Î¶óÀ̾ðÆ® / GPU¼­¹ö / ¹Ì´Ï¼­¹ö·º / ¼­¹ö¿ëPC / Á¨¼­¹ö / AI¼­¹ö / Á¦¿Â¼­¹ö / ¼­¹ö°¡°Ý / 1U¼­¹ö / HPDL20Gen10 / HP¼­¹ö8SFF800W / °¡»ó¼­¹ö / Ÿ¿öÇü¼­¹ö / HPDL360 / HPDL380Gen10 / ÄÄÇ»Åͼ­¹ö / ¹Ìµð¾î¼­¹ö / Ÿ¿ö¼­¹ö / DB¼­¹ö / HP¼­¹ö580 / HP¼­¹öÆÄ¿ö / HPDL360Gen10 / À©µµ¿ì¼­¹öÄÄÇ»ÅÍ / XEON¼­¹ö / 881457-B21

ÄÚ¸àÆ® ¾²±â
ÄÚ¸àÆ® ¾²±â
°Ô½Ã±Û ¸ñ·Ï
Content
Name
Date
Hits
2023-12-26
295

ºñ¹Ð¹øÈ£ È®ÀÎ ´Ý±â