English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12014
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS À¥ ¼­¹ö´Â ¿Ã¹Ù¸£Áö ¸øÇÑ À¥ Æû(form) 󸮷ΠÀÎÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
FrontPage Server Extensions (FPSE)´Â IIS 4.0°ú 5.0¿¡ °°ÀÌ Æ÷ÇÔµÇ¾î ¼³Ä¡ ½Ã µðÆúÆ®·Î ¼³Ä¡µÈ´Ù.
FPSEÀÇ °¡Àå Àß ¾Ë·ÁÁø ±â´ÉÀº ¿ø°ÝÀ̳ª ·ÎÄà »óÀÇ À¥ ÆäÀÌÁö ¹× À¥ ÄÁÅÙÆ®(Content)¸¦ °ü¸®ÇÏ´Â °ÍÀÌÁö¸¸, ÀÌ ¿Ü¿¡µµ »ç¿ëÀÚ¿¡ ÀÇÇØ Á¦½ÃµÈ À¥ Æû(web form)µéÀÇ Ã³¸®¸¦ µµ¿ÍÁÖ´Â ±â´ÉÀ» Æ÷ÇÔÇϰí ÀÖ´Â browse-time Áö¿ø±â´Éµµ °¡Áö°í ÀÖ´Ù.
Ãë¾àÁ¡Àº ÀÌ·¯ÇÑ ÇÔ¼öµé Áß Çϳª¿¡¼­ ¹ß°ßµÇ´Âµ¥, shtml È£Ãâ ¹× FrontPage Authoring ¸ðµâÀÎ author.dll ¿¡ ÁúÀÇ(Query)°¡ ¿äûµÉ ¶§ À̸¦ ¿Ã¹Ù¸£°Ô ó¸®ÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ·¯ÇÑ ¸ðµâ¿¡ Àß Á¶ÀÛµÈ ÁúÀÇ(Query)¸¦ º¸³¿À¸·Î½á FrontPage¸¦ Å©·¡½¬(crash)½Ã۰í Windows NT 4.0ÀÇ °æ¿ì¿¡´Â inetinfo.exe Á¾·áµÇ¾î ´õ ÀÌ»óÀÇ ¼­ºñ½º°¡ ºÒ°¡´ÉÇÏ°Ô µÈ´Ù. ÇÏÁö¸¸, Windows 2000ÀÇ °æ¿ì´Â inetinfo.exe´Â Á¾·áµÇÁö ¾Ê¾Æ À¥ ¼­¹ö¿ÍÀÇ ¿¬°áÀº ÀÌ·ç¾îÁö³ª GET, HEAD, ..µî°ú °°Àº ¸í·É¾îµéÀÇ Ã³¸®°¡ ºÒ°¡´ÉÇØÁø´Ù.

* ¾Ë¸²: ¼­¹ö°¡ Á¤»óÀûÀÎ µ¿ÀÛÀ» Çϱâ À§Çؼ­´Â ÀçºÎÆÃÀÌ ¹Ýµå½Ã ÇÊ¿äÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/2144
http://www.microsoft.com/technet/security/bulletin/MS00-100.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft IIS 4.0
- Microsoft Windows NT 4.0 Option Pack
- Microsoft BackOffice 4.0/4.5
Microsoft IIS 5.0
- Windows 2000 Any version
ÇØ°áÃ¥ Ãë¾àÁ¡À» À§ÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.

Microsoft IIS 4.0:
http://download.microsoft.com/download/winntsrv40/Patch/q280322/NT4/EN-US/Q280322i.EXE

Microsoft IIS 5.0:
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=5034

-- ¶Ç´Â --

Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡°¡ Æ÷ÇԵǾî ÀÖ´Â ¼­ºñ½º ÆÑÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù.

Microsoft IIS 4.0ÀÇ °æ¿ì, Windows NT 4.0 ¼­ºñ½º ÆÑ 6a¸¦ ¼³Ä¡ÇÑ´Ù.

Microsoft IIS 5.0ÀÇ °æ¿ì, windows ¼­ºñ½º ÆÑ 2¸¦ ¼³Ä¡ÇÑ´Ù.

¡Ø Microsoft»ç´Â ´õ ÀÌ»ó Windows 2000 ¹× Windows NT 4.0À» Áö¿øÇÏÁö ¾Ê´Â´Ù. Vender¿¡ ¹®ÀÇÇÏ¿© Windows NT 4.0 ¼­ºñ½º ÆÑ 6a ¶Ç´Â Windows 2000 ¼­ºñ½º ÆÑ 2 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
°ü·Ã URL CVE-2001-0096 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)