Ãë¾àÁ¡ID |
12014 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç IIS À¥ ¼¹ö´Â ¿Ã¹Ù¸£Áö ¸øÇÑ À¥ Æû(form) 󸮷ΠÀÎÇÑ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. FrontPage Server Extensions (FPSE)´Â IIS 4.0°ú 5.0¿¡ °°ÀÌ Æ÷ÇÔµÇ¾î ¼³Ä¡ ½Ã µðÆúÆ®·Î ¼³Ä¡µÈ´Ù. FPSEÀÇ °¡Àå Àß ¾Ë·ÁÁø ±â´ÉÀº ¿ø°ÝÀ̳ª ·ÎÄà »óÀÇ À¥ ÆäÀÌÁö ¹× À¥ ÄÁÅÙÆ®(Content)¸¦ °ü¸®ÇÏ´Â °ÍÀÌÁö¸¸, ÀÌ ¿Ü¿¡µµ »ç¿ëÀÚ¿¡ ÀÇÇØ Á¦½ÃµÈ À¥ Æû(web form)µéÀÇ Ã³¸®¸¦ µµ¿ÍÁÖ´Â ±â´ÉÀ» Æ÷ÇÔÇϰí ÀÖ´Â browse-time Áö¿ø±â´Éµµ °¡Áö°í ÀÖ´Ù. Ãë¾àÁ¡Àº ÀÌ·¯ÇÑ ÇÔ¼öµé Áß Çϳª¿¡¼ ¹ß°ßµÇ´Âµ¥, shtml È£Ãâ ¹× FrontPage Authoring ¸ðµâÀÎ author.dll ¿¡ ÁúÀÇ(Query)°¡ ¿äûµÉ ¶§ À̸¦ ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ·¯ÇÑ ¸ðµâ¿¡ Àß Á¶ÀÛµÈ ÁúÀÇ(Query)¸¦ º¸³¿À¸·Î½á FrontPage¸¦ Å©·¡½¬(crash)½Ã۰í Windows NT 4.0ÀÇ °æ¿ì¿¡´Â inetinfo.exe Á¾·áµÇ¾î ´õ ÀÌ»óÀÇ ¼ºñ½º°¡ ºÒ°¡´ÉÇÏ°Ô µÈ´Ù. ÇÏÁö¸¸, Windows 2000ÀÇ °æ¿ì´Â inetinfo.exe´Â Á¾·áµÇÁö ¾Ê¾Æ À¥ ¼¹ö¿ÍÀÇ ¿¬°áÀº ÀÌ·ç¾îÁö³ª GET, HEAD, ..µî°ú °°Àº ¸í·É¾îµéÀÇ Ã³¸®°¡ ºÒ°¡´ÉÇØÁø´Ù.
* ¾Ë¸²: ¼¹ö°¡ Á¤»óÀûÀÎ µ¿ÀÛÀ» Çϱâ À§Çؼ´Â ÀçºÎÆÃÀÌ ¹Ýµå½Ã ÇÊ¿äÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/2144 http://www.microsoft.com/technet/security/bulletin/MS00-100.asp
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft IIS 4.0 - Microsoft Windows NT 4.0 Option Pack - Microsoft BackOffice 4.0/4.5 Microsoft IIS 5.0 - Windows 2000 Any version |
ÇØ°áÃ¥ |
Ãë¾àÁ¡À» À§ÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.
Microsoft IIS 4.0: http://download.microsoft.com/download/winntsrv40/Patch/q280322/NT4/EN-US/Q280322i.EXE
Microsoft IIS 5.0: http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=5034
-- ¶Ç´Â --
Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡°¡ Æ÷ÇԵǾî ÀÖ´Â ¼ºñ½º ÆÑÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
Microsoft IIS 4.0ÀÇ °æ¿ì, Windows NT 4.0 ¼ºñ½º ÆÑ 6a¸¦ ¼³Ä¡ÇÑ´Ù.
Microsoft IIS 5.0ÀÇ °æ¿ì, windows ¼ºñ½º ÆÑ 2¸¦ ¼³Ä¡ÇÑ´Ù.
¡Ø Microsoft»ç´Â ´õ ÀÌ»ó Windows 2000 ¹× Windows NT 4.0À» Áö¿øÇÏÁö ¾Ê´Â´Ù. Vender¿¡ ¹®ÀÇÇÏ¿© Windows NT 4.0 ¼ºñ½º ÆÑ 6a ¶Ç´Â Windows 2000 ¼ºñ½º ÆÑ 2 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. |
°ü·Ã URL |
CVE-2001-0096 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|