Samba ๋ฐ MIT/Heimdal Kerberos์˜ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ ์ทจ์•ฝ์ 

Samba 4.17.3, 4.16.7 ๋ฐ 4.15.12 ํŒจํ‚ค์ง€์˜ ์ˆ˜์ • ๋ฆด๋ฆฌ์Šค๊ฐ€ ๊ณต๊ฐœ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ๋ฆด๋ฆฌ์Šค์—์„œ๋Š” Kerberos ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ์ทจ์•ฝ์ (CVE-2022-42898)์ด ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ์ธ์ฆ๋œ ์‚ฌ์šฉ์ž๊ฐ€ ๋ณด๋‚ธ PAC(ํŠน๊ถŒ ์†์„ฑ ์ธ์ฆ์„œ) ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ฒ˜๋ฆฌํ•  ๋•Œ ์ •์ˆ˜ ์˜ค๋ฒ„ํ”Œ๋กœ๋ฅผ ๋ฐœ์ƒ์‹œํ‚ค๊ณ  ํ• ๋‹น๋œ ๋ฒ„ํผ๋ฅผ ์ดˆ๊ณผํ•˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์”๋‹ˆ๋‹ค. ๋ฐฐํฌํŒ์˜ ํŒจํ‚ค์ง€ ์—…๋ฐ์ดํŠธ ๊ฒŒ์‹œ ํ˜„ํ™ฉ์€ Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD ํŽ˜์ด์ง€์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๋Š” Samba ์™ธ์—๋„ MIT Kerberos ๋ฐ Heimdal Kerberos ํŒจํ‚ค์ง€์—๋„ ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. Samba ์ทจ์•ฝ์  ๋ณด๊ณ ์„œ์—๋Š” ์œ„ํ˜‘์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์ด ๋‚˜์™€ ์žˆ์ง€ ์•Š์ง€๋งŒ, MIT Kerberos ๋ณด๊ณ ์„œ๋Š” ์ด ์ทจ์•ฝ์ ์ด ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ๋‹ค๊ณ  ๋ช…์‹œํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ 32๋น„ํŠธ ์‹œ์Šคํ…œ์—์„œ๋งŒ ์•…์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๋Š” KDC(ํ‚ค ๋ฐฐํฌ ์„ผํ„ฐ) ๋˜๋Š” kadmind๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ตฌ์„ฑ์— ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. Active Directory๊ฐ€ ์—†๋Š” ๊ตฌ์„ฑ์—์„œ๋Š” ํŒŒ์ผ ์‹œ์Šคํ…œ์—์„œ๋„ ์ด ์ทจ์•ฝ์ ์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. ์„œ๋ฒ„ Kerberos๋ฅผ ์‚ฌ์šฉํ•˜๋Š” Samba์—์„œ ๋ฐœ์ƒํ•œ ๋ฌธ์ œ์˜€์Šต๋‹ˆ๋‹ค. krb5_parse_pac() ํ•จ์ˆ˜์— ๋ฒ„๊ทธ๊ฐ€ ์žˆ์—ˆ๋Š”๋ฐ, ์ด ํ•จ์ˆ˜๊ฐ€ PAC ํ•„๋“œ๋ฅผ ํŒŒ์‹ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ฒ„ํผ ํฌ๊ธฐ๋ฅผ ์ž˜๋ชป ๊ณ„์‚ฐํ–ˆ์Šต๋‹ˆ๋‹ค. 32๋น„ํŠธ ์‹œ์Šคํ…œ์—์„œ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ PAC๋ฅผ ์ฒ˜๋ฆฌํ•  ๋•Œ, ์ด ๋ฒ„๊ทธ๋กœ ์ธํ•ด ๊ณต๊ฒฉ์ž๊ฐ€ ์ „์†กํ•œ 16๋ฐ”์ดํŠธ ๋ธ”๋ก์ด ํ• ๋‹น๋œ ๋ฒ„ํผ๋ฅผ ๋ฒ—์–ด๋‚˜ ๋ฐฐ์น˜๋  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru