ÀÌ SECTION¿¡¼ ¼Ò°³ÇÏ´Â PACKAGE¸¦ »ç¿ëÇÏÁö ¸»¶ó. ¹®Á¦Á¡ÀÌ ¹ß°ßµÇ¾ú´Ù
ÃÖÃÊ·Î Shadow Suite¸¦ ¸¸µç »ç¶÷Àº John F. Haugh II
ÀÌ´Ù.
Linux system¿¡¼ »ç¿ëµÇ´Â °ÍÀ¸·Î´Â ´ÙÀ½°ú °°Àº °ÍµéÀÌ ÀÖ´Ù.
shadow-3.3.1
°¡ ¿øº»ÀÌ´Ù.shadow-3.3.1-2
´Â
Florian La Roche <flla@stud.uni-sb.de>¾¾¿¡ ÀÇÇؼ Linux¿¡ ¸Â°Ô
°íÃÄÁ³°í, Á» ´õ ³ª¾ÆÁø °ÍÀÌ ÀÖ´Ù.shadow-mk
´Â Linux¿¡ ¸ÂÃß¾î ±¸¼ºµÇ¾î ÀÖ´Ù.shadow-mk
package´Â shadow-3.3.1-2 patch
°¡ Àû¿ëµÈ,
John F. Haugh II
¾¾¿¡ ÀÇÇØ ¹èÆ÷µÈ shadow-3.3.1
package¸¦
Æ÷ÇÔÇÏ°í ÀÖ´Ù. °Å±â¿¡ Á» ´õ ¼³Ä¡°¡ ½±°Ô
Mohan Kokal <magnus@texas.net>¾¾²²¼ Á¶±Ý °íÄ¡°í,
Joseph R.M. Zbiciak
¾¾²²¼ /bin/loginÀÇ -f, -h º¸¾È ±¸¸ÛÀ» Á¦°ÅÇÑ
login1.c
(login.secure)°¡ µ¡ ºÙ¿©Áö°í, ¸î¸î ´Ù¸¥ Àâ´ÙÇÑ patch°¡
Àû¿ëµÇ¾î ÀÖ´Ù.
shadow.mk
package´Â ÇöÀç login
program¿¡
º¸¾È»ó ÇãÁ¡°¡ ÀÖ¾î Á¶¸¸°£ ´ëüµÉ °ÍÀÌ´Ù.
Shadow 3.3.1, 3.3.1-2, shadow-mk´Â login
program¿¡
º¸¾È»ó ÇãÁ¡ÀÌ ÀÖ´Ù. ÀÌ login
bug´Â login nameÀÇ ±æÀ̸¦
°Ë»çÇÏÁö ¾Ê´Â °ÍÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. ÀÌ °ÍÀº Ãæµ¹ ¶Ç´Â ´õ ³ª»Û °ÍÀ» À¯¹ß½ÃÅ°´Â
buffer overflow¸¦ ¹ß»ý½ÃŲ´Ù. ÀÌ buffer overflow°¡, ÀÌ bug¿Í ÇÔ²² shared
library¸¦ »ç¿ëÇÏ´Â system¿¡¼ ¾î¶² »ç¿ëÀÚ¿¡°Ô root ±ÇÇÑÀ» ÁشٴÂ
¼Ò¹®ÀÌ ÀÖ¾î ¿Ô´Ù. ³ª´Â ¾î¶»°Ô ÀÌ·± ÀÏÀÌ °¡´ÉÇÑÁö ±¸Ã¼ÀûÀ¸·Î °Å·ÐÇÏÁö ¾Ê°Ú´Ù.
±× ÀÌÀ¯´Â ÀÌ·± (bug°¡ ÀÖ´Â) Shadow Suite¸¦ ¼³Ä¡Çؼ ÇÇÇظ¦ ÀÔÀ» ¼ö
ÀÖ´Â Linux systemÀÌ ¸¹°í, Shadow SuiteÀÌ ¾ø´Â ELF-ÀÌÀü
¹èÆ÷ÆÇ¿¡°Ôµµ À§ÇèÇϱ⠶§¹®ÀÌ´Ù.
ÀÌ ¹®Á¦¿Í ´Ù¸¥ Linux º¸¾È°ü·Ã ¹®Á¦¿¡ ´ëÇØ ´õ ÀÚ¼¼È÷ ¾Ë°í ½Í´Ù¸é, Linux Security home page (Shared Libraries and login Program Vulnerability)¸¦ ÂüÁ¶Ç϶ó.
±ÇÇÒ¸¸ÇÑ Shadow SuiteÀº ¾ÆÁ÷ BETA testingÁßÀÌ´Ù. ¾î·µç ÃÖ±Ù versionÀÌ
¾ÈÀüÇϸç, Ãë¾àÇÑ login
programÀ» Æ÷ÇÔÇÏÁö ¾Ê´Â´Ù.
package´Â ´ÙÀ½°ú °°Àº ¸í¸í±ÔÄ¢À» °®´Â´Ù:
shadow-YYMMDD.tar.gz
YYMMDD
´Â Suite°¡ ¹ßÇ¥µÈ ³¯Â¥ÀÌ´Ù.
ÀÌ versionÀº Beta testingÀÌ ³¡³ª¸é, °á±¹ Version 3.3.3ÀÌ µÉ°ÍÀÌ°í, Marek Michalkiewicz <marekm@i17linuxb.ists.pwr.wroc.pl>¿¡ ÀÇÇؼ À¯Áöº¸¼ö µÇ°í ÀÖ´Ù. shadow-current.tar.gz¿¡¼ ¾òÀ» ¼ö ÀÖ´Ù.
¶ÇÇÑ, ´ÙÀ½¿¡ ³ª¿À´Â mirror siteµé¿¡¼ ¾òÀ» ¼ö ÀÖ´Ù:
ÇöÀç ³ª¿ÍÀÖ´Â versionÀ» »ç¿ëÇϱ⠹ٶõ´Ù.
shadow-960129
º¸´Ù ÀÌÀü¿¡ ³ª¿Â versionÀ» ¾²Áö ¸»±â ¹Ù¶õ´Ù:
¾Õ¿¡¼ ³íÀÇÇÑ login
º¸¾È ÇãÁ¡ÀÌ ÀÖ´Ù.
ÀÌ ¹®¼¿¡¼ Shadow Suite¶ó°í ¸»ÇÏ´Â °ÍÀº ÀÌ versionÀ» °¡¸®Å²´Ù. ¶ÇÇÑ, ´ç½ÅÀÌ »ç¿ëÇÏ°í ÀÖ´Â package¶ó°í °¡Á¤ÇÑ´Ù.
Âü°íÀûÀ¸·Î, ¼³Ä¡ ¾È³»¼¸¦ ÀÛ¼ºÇÏ´Â µ¥, shadow-960129
¸¦ »ç¿ëÇß´Ù.
ÀÌÀü¿¡ shadow-mk
¸¦ »ç¿ëÇß´Ù¸é, ÀÌ versionÀ¸·Î upgrade¸¦ ÇÏ°í, ÀÌÀü¿¡
compileÇß´ø °ÍÀ» ´Ù½Ã Çϱ⠹ٶõ´Ù.
Shadow Suite´Â ´ÙÀ½ programÀÇ ´ëüǰÀ» °¡Áö°í ÀÖ´Ù:
su, login, passwd, newgrp, chfn, chsh, id
¶ÇÇÑ, »õ·Î¿î programµéµµ ÀÖ´Ù:
chage, newusers, dpasswd, gpasswd, useradd, userdel, usermod, groupadd,
groupdel, groupmod, groups, pwck, grpck, lastlog, pwconv, pwunconv
µ¡ºÙ¿©, library: libshadow.a
°¡ »ç¿ëÀÚ password¿¡ Á¢±ÙÇÏ´Â programÀ»
ÀÛ¼ºÇϰųª compileÇϱâ À§ÇØ Æ÷ÇԵǾî ÀÖ´Ù.
¶ÇÇÑ, programµéÀ» À§ÇÑ manual pageµµ ÀÖ´Ù.
/etc/login.defs
·Î ¼³Ä¡µÇ´Â login programÀÇ ¼³Á¤ fileµµ ÀÖ´Ù.