Ãë¾àÁ¡ID |
12015 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç IIS À¥ ¼¹ö´Â Front Page ISAPI ÇÊÅÍ¿Í °ü·ÃµÈ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Front Page´Â µ¿Àû ÄÄÆ÷³ÍÆ®µéÀÎ shtml.exe/dll¸¦ ó¸®Çϱâ À§ÇÑ URL ÆÄ¼(parser)µéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù. ±×·±µ¥, ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ µ¿Àû ÄÄÆ÷³ÍÆ®µéÀ» À§ÇÑ Á¤»óÀûÀÎ ¿äû URL, /_vti_bin/shtml.exe, À» ´ë½ÅÇÏ¿© °úµµÇÏ°Ô ±ä URLÀ» ¼¹ö¿¡ Àü´ÞÇÏ°Ô µÇ¸é, ISAPI ÇÊÅÍÀÇ ¼ºê ¸ðµâµéÀº ´ë»ó URLÀ» ÇÊÅ͸µÇÑ ÈÄ Null °ªÀ» À¥ ¼¹öÀÇ URL ÆÄ¼(parser)¿¡°Ô ¹ÝȯÇÏ°Ô µÈ´Ù. À̰ÍÀº ¼¹ö¿¡ Access ViolationÀ» ÀÏÀ¸Å³ ¼ö ÀÖÀ¸¸ç IIS ¼¹öÀÇ ÇÑ ÆÐŰÁö·Î ÇÁ·Î¼¼½º Á¤º¸¸¦ ó¸®ÇÏ´Â inetinfo.exeÀ» Á¾·á½ÃŲ´Ù. IIS 4.0 ¼¹öÀÇ °æ¿ì´Â ÀÌ·¯ÇÑ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ¸¸é, ¼¹öÀÇ Á¤»óÀûÀÎ µ¿ÀÛÀ» À§Çؼ »ç¿ëÀÚ°¡ ¼öµ¿À¸·Î(manually) ÀçºÎÆÃÀ» ÇØ¾ß ÇÏÁö¸¸ IIS 5.0 °ú 5.1 ¼¹öÀÇ °æ¿ì´Â ¼¹ö ÀÚüÀûÀ¸·Î ÀçºÎÆÃÀÌ µÈ´Ù. ÇÏÁö¸¸, ¼¹ö°¡ iisresetÀ» ÅëÇØ ÀÚüÀûÀ¸·Î ¼ºñ½º¸¦ ÀçºÎÆÃÇÑ´Ù ÇÒÁö¶óµµ À̰ÍÀº Àá±ñ µ¿¾È¸¸ À¯È¿ÇÒ »Ó °ü¸®ÀÚ°¡ ¼öµ¿À¸·Î(manually) ¼ºñ½º³ª ¼¹ö ½Ã½ºÅÛÀ» ÀçºÎÆÃÇϱâ Àü±îÁö´Â ¼ºñ½º´Â Å©·¡½¬(crash)µÈ ä ³²¾ÆÀÖ°Ô µÈ´Ù. ÀÌ Ãë¾àÁ¡Àº Cisco Á¦Ç° ÀÚüÀÇ ¹ö±×´Â ¾Æ´ÏÁö¸¸ IIS ¼¹ö°¡ ±¸µ¿µÇ´Â ¸¹Àº Cisco Á¦Ç°¿¡µµ ¿µÇâÀ» ³¢Ä£´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/4479 http://www.microsoft.com/technet/security/bulletin/MS02-018.asp
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æûµé : Microsoft IIS 4.0 Microsoft IIS 5.0 Microsoft IIS 5.1 Cisco Buildig Broadband Service Manager Cisco Call Manager Cisco Unity Server |
ÇØ°áÃ¥ |
º» Ãë¾àÁ¡°ú ¶Ç ´Ù¸¥ Ãë¾àÁ¡µé¿¡ ´ëÇÑ ÇØ°áÃ¥À» Á¦°øÇÏ´Â Cumulative ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
* For Microsoft IIS 4.0 : ÆÐÄ¡ Q319733 IIS 4.0 http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q319733i.exe ¼ºñ½º ÆÑ Q317636 http://support.microsoft.com/kb/317636
* For Microsoft IIS 5.0 : ÆÐÄ¡ Q319733 IIS 5.0 http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q319733_W2K_SP3_X86_EN.exe
* For Microsoft IIS 5.1 : ÆÐÄ¡ Q319733 IIS 5.1 http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q319733_WXP_SP1_x86_ENU.exe
* For Cisco products : Cisco Á¦Ç°À» À§ÇØ MS¿¡¼ Á¦°øÇÏ´Â cumulative ÆÐÄ¡´Â ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÑ´Ù. http://online.securityfocus.com/bid/4479/solution/ for Microsoft's cumulative patch.
-- ¶Ç´Â --
shtml/shtm ISAPI ÇÊÅÍÀÇ ¸ÅÇÎÀ» Á¦°ÅÇØ¾ß ÇÑ´Ù. (windows 2000 ±âÁØ) 1. Á¦¾îÆÇ ¡æ °ü¸®µµ±¸ ¡æ ÀÎÅÍ³Ý ¼ºñ½º °ü¸®¸¦ ¿¬´Ù. 2. À¥ ¼¹öÀÇ "µî·ÏÁ¤º¸"¸¦ ¼±ÅÃÇÑ´Ù. 3. Ȩ µð·ºÅ丮 ÅÇÀ» ¼±ÅÃÇÑ ÈÄ ÀÀ¿ë ÇÁ·Î±×·¥ ¼³Á¤¿¡¼ ±¸¼ºÀ» Ŭ¸¯ÇÑ´Ù. 4. ÀÀ¿ë ÇÁ·Î±×·¥ ¸ÅÇÎ ÅÇ¿¡¼ .shtml/shtm ¿Í sht ¸¦ ¼±ÅÃÇÑ ÈÄ Á¦°Å¹öưÀ» Ŭ¸¯ÇÑ´Ù. 5. È®ÀÎ ÈÄ Á¾·áÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-0072 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|