Note: The original document is newer than this translation.
º¸¾È Á¤º¸
µ¥ºñ¾ÈÀº º¸¾È ¹®Á¦¸¦ ¸Å¿ì ÁøÁöÇÏ°Ô ´ëÇÕ´Ï´Ù. ¿ì¸®´Â ¸ðµç º¸¾È ¹®Á¦¸¦
ÁÖÀÇ ±í°Ô ´Ù·ç°í ÀûÀýÇÑ ½Ã°£ ¾È¿¡ °íĨ´Ï´Ù.
¸¹Àº º¸¾È ±Ç°í¿¡ ´ëÇØ ´Ù¸¥ ÀÚÀ¯ ¼ÒÇÁÆ®¿þ¾î º¥´õ¿Í Çù·ÂÇϰí Ãë¾à¼ºÀÌ
°ø°³µÇ´Â °°Àº ³¯ ¹ßÇ¥ÇÕ´Ï´Ù. ¿ì¸®´Â ¶ÇÇÑ º¸¾È
°¨»ç(Security Audit) ÆÀÀ» µÎ¾î ¾ÆÅ°À̺긦 ¸®ºäÇØ »õ·Ó°Å³ª °íÃÄÁöÁö ¾ÊÀº º¸¾È ¹ö±×¸¦
ã½À´Ï´Ù.
"º¸¾È ¹®Á¦¸¦ ¼û±â´Â °Í"ÀÌ ÇØ°áÃ¥ÀÌ ¾Æ´ÔÀ» ¿ì¸®´Â °æÇèÀûÀ¸·Î ¾Ë°í ÀÖ½À´Ï´Ù.
º¸¾È ¹®Á¦¸¦ °ø°³ÇÔÀ¸·Î½á ´õ¿í ºü¸£°í ÁÁÀº ÇØ°áÃ¥À» ¾òÀ» ¼ö ÀÖ½À´Ï´Ù. ±×·¯ÇÑ
¸Æ¶ô¿¡¼ ÀáÀçÀûÀ¸·Î µ¥ºñ¾È¿¡ ¿µÇâÀ» ³¢Ä¥ ¼ö ÀÖ´Â ¾Ë·ÁÁø º¸¾È ±¸¸Û°ú °ü·ÃµÈ µ¥ºñ¾ÈÀÇ ÇöÀç »óȲÀ» ÀÌ ÆäÀÌÁö¿¡
³ªÅ¸³Â½À´Ï´Ù.
µ¥ºñ¾ÈÀº ¶ÇÇÑ º¸¾È Ç¥ÁØÈ ÀÛ¾÷¿¡ Âü¿©Çϰí ÀÖ½À´Ï´Ù.
µ¥ºñ¾È º¸¾È ±Ç°í(Debian Security Advisories)´Â
CVE¿Í ȣȯµÇ¸ç
µ¥ºñ¾ÈÀº Open Vulnerability Assessment
Language ÇÁ·ÎÁ§Æ®ÀÇ È¸ÀÇ¿¡µµ Âü¿©Çϰí ÀÖ½À´Ï´Ù.
µ¥ºñ¾È ½Ã½ºÅÛÀ» ¾ÈÀüÇÏ°Ô À¯ÁöÇϱâ
Ãֽе¥ºñ¾È º¸¾È ±Ç°í¸¦ ¹Þ¾Æº¸·Á¸é
debian-security-announce
¸ÞÀϸµ ¸®½ºÆ®¿¡ °¡ÀÔÇϱ⠹ٶø´Ï´Ù.
ÃֽŠº¸¾È ¾÷µ¥ÀÌÆ®¸¦ ½±°Ô ¹ÞÀ¸·Á¸é apt¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
/etc/apt/sources.list ÆÄÀÏ¿¡ ´ÙÀ½°ú °°Àº ÁÙÀ» ³Ö¾îÁÖ¾î¾ß ÇÒ °ÍÀÔ´Ï´Ù.
deb http://security.debian.org/ etch/updates main contrib non-free
µ¥ºñ¾ÈÀÇ º¸¾È ¹®Á¦¿¡ ´ëÇÑ Á»´õ ÀÚ¼¼ÇÑ Á¤º¸´Â º¸¾È ÆÀ
FAQ¿Í Securing DebianÀ» Âü°íÇϼ¼¿ä.
ÀÌ À¥ ÆäÀÌÁöµéÀº debian-security-announce ¸®½ºÆ®¿¡ ¿Ã¶ó¿Â º¸¾È °æ°í¸¦ ¿ä¾àÇÑ(condensed) ¹®¼¸¦
Æ÷ÇÔÇϰí ÀÖ½À´Ï´Ù.
- [2008³â 05¿ù 11ÀÏ] DSA-1573 rdesktop
- several vulnerabilities
- [2008³â 05¿ù 11ÀÏ] DSA-1572 php5
- several vulnerabilities
- [2008³â 05¿ù 06ÀÏ] DSA-1570 kazehakase
- various
- [2008³â 05¿ù 05ÀÏ] DSA-1569 cacti
- insufficient input sanitising
- [2008³â 05¿ù 05ÀÏ] DSA-1568 b2evolution
- insufficient input sanitising
- [2008³â 05¿ù 05ÀÏ] DSA-1567 blender
- buffer overrun
- [2008³â 05¿ù 02ÀÏ] DSA-1566 cpio
- programming error
- [2008³â 05¿ù 01ÀÏ] DSA-1565 linux-2.6
- several vulnerabilities
- [2008³â 05¿ù 01ÀÏ] DSA-1564 wordpress
- multiple vulnerabilities
- [2008³â 04¿ù 30ÀÏ] DSA-1563 asterisk
- programming error
- [2008³â 04¿ù 28ÀÏ] DSA-1562 iceape
- programming error
- [2008³â 04¿ù 28ÀÏ] DSA-1561 ldm
- programming error
- [2008³â 04¿ù 28ÀÏ] DSA-1560 kronolith2
- insufficient input sanitising
- [2008³â 04¿ù 27ÀÏ] DSA-1559 phpgedview
- insufficient input sanitising
- [2008³â 04¿ù 24ÀÏ] DSA-1558 xulrunner
- programming error
- [2008³â 04¿ù 24ÀÏ] DSA-1557 phpmyadmin
- insufficient input sanitising
- [2008³â 04¿ù 24ÀÏ] DSA-1556 perl
- heap buffer overflow
- [2008³â 04¿ù 23ÀÏ] DSA-1555 iceweasel
- programming error
- [2008³â 04¿ù 22ÀÏ] DSA-1554 roundup
- insufficient input sanitising
- [2008³â 04¿ù 20ÀÏ] DSA-1553 ikiwiki
- cross-site request forgery
- [2008³â 04¿ù 19ÀÏ] DSA-1552 mplayer
- missing input sanitising
- [2008³â 04¿ù 19ÀÏ] DSA-1551 python2.4
- several vulnerabilities
- [2008³â 04¿ù 17ÀÏ] DSA-1550 suphp
- programming error
- [2008³â 04¿ù 17ÀÏ] DSA-1549 clamav
- buffer overflows
- [2008³â 04¿ù 17ÀÏ] DSA-1548 xpdf
- several vulnerabilities
- [2008³â 04¿ù 17ÀÏ] DSA-1547 openoffice.org
- several vulnerabilities
Ãֽе¥ºñ¾È º¸¾È ±Ç°í¸¦ RDF Çü½ÄÀ¸·Î º¼ ¼öµµ ÀÖ½À´Ï´Ù. º¸¾È ±Ç°í°¡ ¹«¾ù¿¡ ´ëÇÑ °ÍÀÎÁö º¼ ¼ö ÀÖ°Ô ÇØ´ç ±Ç°íÀÇ Ã¹ ¹øÂ° ´Ü¶ôÀ» Æ÷ÇÔÇÑ µÎ ¹øÂ° ÆÄÀϵµ Á¦°øÇÕ´Ï´Ù.
Á»´õ ¿À·¡µÈ º¸¾È °æ°í´Â ´ÙÀ½ ÆäÀÌÁö¿¡¼ º¼ ¼ö ÀÖ½À´Ï´Ù.
- Security alerts announced in 2008
- Security alerts announced in 2007
- Security alerts announced in 2006
- Security alerts announced in 2005
- Security alerts announced in 2004
- Security alerts announced in 2003
- Security alerts announced in 2002
- Security alerts announced in 2001
- Security alerts announced in 2000
- Security alerts announced in 1999
- Security alerts announced in 1998
- Security alerts announced in 1997
- Undated security alerts, included for posterity.
Debian distributions are not vulnerable to all security problems:
- woody(µ¥ºñ¾È 3.0)(´õ ÀÌ»ó À¯Áöº¸¼öµÇÁö ¾Ê½À´Ï´Ù)
- sarge(µ¥ºñ¾È 3.1)
- etch(µ¥ºñ¾È 4.0)
¿¬¶ôó Á¤º¸
¿ì¸®¿¡°Ô ¿¬¶ôÇϱâ Àü¿¡ º¸¾È ÆÀ FAQ¸¦
Àо¼¼¿ä. Áú¹®¿¡ ´ëÇÑ ´ë´äÀÌ ÀÌ¹Ì ÀÖÀ» °ÍÀÔ´Ï´Ù!
The contact information is in the FAQ as
well.