English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12007
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS À¥ ¼­¹ö´Â ASP chunked encoding Àü¼Û ¸ÞÄ¿´ÏÁò(transfer mechanism)°ú °ü·ÃµÈ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Chunked EncodingÀº À¥ Ŭ¶óÀÌ¾ðÆ®°¡ À¥ ¼­¹ö¿¡°Ô 'chunk' ¶ó°í ºÒ¸®´Â °¡º¯ ±æÀÌÀÇ µ¥ÀÌÅÍ ´ÜÀ§¸¦ Àü¼ÛÇÏ´Â ¹æ¹ýÀ» ¸»Çϸç Chunked Encoding Àü¼Û ¸ÞÄ¿´ÏÁò(Transfer mechanism)Àº ASP¸¦ ±¸ÇöÇÏ´Â ISAPI(Internet Services Application Programming Interface)ÀÇ ÀϺκÐÀÌ´Ù. Ŭ¶óÀÌ¾ðÆ®°¡ ¼­¹ö¿¡°Ô µ¥ÀÌÅ͸¦ Àü¼ÛÇϱâ Àü¿¡ 'chunked' µ¥ÀÌÅÍ Å©±â¸¦ ¼­¹ö¿¡ ¾Ë¸®¸é ¼­¹ö´Â ÀÌ¿¡ ¾Ë¸ÂÀº Å©±âÀÇ ¹öÆÛ¸¦ ÇÒ´çÇÏ°Ô µÈ´Ù. ±×·¯³ª, IIS ¼­¹ö¿¡´Â chunk¸¦ ´ãÀ» ¹öÆÛ Å©±â¸¦ °è»êÇÏ´Â ¹æ¹ý »óÀÇ »ê¼úÀûÀÎ ¿À·ù·Î ÀÎÇÏ¿© ½ÇÁ¦º¸´Ù ÀÛÀº Å©±âÀÇ ¹öÆÛ¸¦ ÇÒ´çÇÏ°Ô µÇ°í °ø°ÝÀÚµéÀº À̸¦ ÀÌ¿ëÇÑ ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ¹öÆÛ ¿À¹öÇ÷οì´Â chunk ¸¦ ÀúÀåÇÏ´Â µ¥ »ç¿ëµÇ´Â ¹öÆÛ°¡ ¸Þ¸ð¸®ÀÇ Èü(heap) ºÎºÐ¿¡ ÇÒ´çµÇ±â ¶§¹®¿¡ heap ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì¶ó ºÒ¸°´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í IIS ¼­¹öÀÇ Á¤»óÀûÀÎ µ¿ÀÛÀ» ¹æÇØÇÒ ¼ö ÀÖÀ¸¸ç, ¶Ç´Â ASP ISAPI extension (ASP.DLL) ±ÇÇÑÀ¸·Î ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms02-018.asp
http://online.securityfocus.com/bid/4485
ÇØ°áÃ¥ ÇØ´ç ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.

* Microsoft IIS 4.0(Windows NT 4.0 Workstation, Server, Enterprise Edition) :
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=12360

* Microsoft IIS 4.0(Windows NT 4.0 Server, Terminal Server Edition) :
http://support.microsoft.com/kb/317636

* Microsoft IIS 5.0 :
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=12360

* Microsoft IIS 5.1 :
http://www.microsoft.com/download/en/details.aspx?DisplayLang=en&id=13790

* IIS À¥ ¼­¹ö°¡ ±¸µ¿ ÁßÀÎ Cisco Á¦Ç° :
Ãë¾àÇÑ Á¦Ç°À̳ª ¾÷µ¥ÀÌÆ® Á¤º¸¸¦ À§ÇØ Cisco Security Advisory »çÀÌÆ®¸¦ Âü°íÇÑ´Ù:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018
°ü·Ã URL CVE-2002-0079 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)