English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12015
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS À¥ ¼­¹ö´Â Front Page ISAPI ÇÊÅÍ¿Í °ü·ÃµÈ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Front Page´Â µ¿Àû ÄÄÆ÷³ÍÆ®µéÀÎ shtml.exe/dll¸¦ ó¸®Çϱâ À§ÇÑ URL ÆÄ¼­(parser)µéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù. ±×·±µ¥, ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ µ¿Àû ÄÄÆ÷³ÍÆ®µéÀ» À§ÇÑ Á¤»óÀûÀÎ ¿äû URL, /_vti_bin/shtml.exe, À» ´ë½ÅÇÏ¿© °úµµÇÏ°Ô ±ä URLÀ» ¼­¹ö¿¡ Àü´ÞÇÏ°Ô µÇ¸é, ISAPI ÇÊÅÍÀÇ ¼­ºê ¸ðµâµéÀº ´ë»ó URLÀ» ÇÊÅ͸µÇÑ ÈÄ Null °ªÀ» À¥ ¼­¹öÀÇ URL ÆÄ¼­(parser)¿¡°Ô ¹ÝȯÇÏ°Ô µÈ´Ù. À̰ÍÀº ¼­¹ö¿¡ Access ViolationÀ» ÀÏÀ¸Å³ ¼ö ÀÖÀ¸¸ç IIS ¼­¹öÀÇ ÇÑ ÆÐŰÁö·Î ÇÁ·Î¼¼½º Á¤º¸¸¦ ó¸®ÇÏ´Â inetinfo.exeÀ» Á¾·á½ÃŲ´Ù. IIS 4.0 ¼­¹öÀÇ °æ¿ì´Â ÀÌ·¯ÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ¸¸é, ¼­¹öÀÇ Á¤»óÀûÀÎ µ¿ÀÛÀ» À§Çؼ­ »ç¿ëÀÚ°¡ ¼öµ¿À¸·Î(manually) ÀçºÎÆÃÀ» ÇØ¾ß ÇÏÁö¸¸ IIS 5.0 °ú 5.1 ¼­¹öÀÇ °æ¿ì´Â ¼­¹ö ÀÚüÀûÀ¸·Î ÀçºÎÆÃÀÌ µÈ´Ù. ÇÏÁö¸¸, ¼­¹ö°¡ iisresetÀ» ÅëÇØ ÀÚüÀûÀ¸·Î ¼­ºñ½º¸¦ ÀçºÎÆÃÇÑ´Ù ÇÒÁö¶óµµ À̰ÍÀº Àá±ñ µ¿¾È¸¸ À¯È¿ÇÒ »Ó °ü¸®ÀÚ°¡ ¼öµ¿À¸·Î(manually) ¼­ºñ½º³ª ¼­¹ö ½Ã½ºÅÛÀ» ÀçºÎÆÃÇϱâ Àü±îÁö´Â ¼­ºñ½º´Â Å©·¡½¬(crash)µÈ ä ³²¾ÆÀÖ°Ô µÈ´Ù. ÀÌ Ãë¾àÁ¡Àº Cisco Á¦Ç° ÀÚüÀÇ ¹ö±×´Â ¾Æ´ÏÁö¸¸ IIS ¼­¹ö°¡ ±¸µ¿µÇ´Â ¸¹Àº Cisco Á¦Ç°¿¡µµ ¿µÇâÀ» ³¢Ä£´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/4479
http://www.microsoft.com/technet/security/bulletin/MS02-018.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æûµé :
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
Cisco Buildig Broadband Service Manager
Cisco Call Manager
Cisco Unity Server
ÇØ°áÃ¥ º» Ãë¾àÁ¡°ú ¶Ç ´Ù¸¥ Ãë¾àÁ¡µé¿¡ ´ëÇÑ ÇØ°áÃ¥À» Á¦°øÇÏ´Â Cumulative ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.

* For Microsoft IIS 4.0 :
ÆÐÄ¡ Q319733 IIS 4.0
http://download.microsoft.com/download/iis40/Patch/Q319733/NT4/EN-US/Q319733i.exe
¼­ºñ½º ÆÑ Q317636
http://support.microsoft.com/kb/317636

* For Microsoft IIS 5.0 :
ÆÐÄ¡ Q319733 IIS 5.0
http://download.microsoft.com/download/iis50/Patch/Q319733/NT5/EN-US/Q319733_W2K_SP3_X86_EN.exe

* For Microsoft IIS 5.1 :
ÆÐÄ¡ Q319733 IIS 5.1
http://download.microsoft.com/download/iis50/Patch/Q319733/WXP/EN-US/Q319733_WXP_SP1_x86_ENU.exe

* For Cisco products :
Cisco Á¦Ç°À» À§ÇØ MS¿¡¼­ Á¦°øÇÏ´Â cumulative ÆÐÄ¡´Â ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÑ´Ù.
http://online.securityfocus.com/bid/4479/solution/ for Microsoft's cumulative patch.

-- ¶Ç´Â --

shtml/shtm ISAPI ÇÊÅÍÀÇ ¸ÅÇÎÀ» Á¦°ÅÇØ¾ß ÇÑ´Ù. (windows 2000 ±âÁØ)
1. Á¦¾îÆÇ ¡æ °ü¸®µµ±¸ ¡æ ÀÎÅÍ³Ý ¼­ºñ½º °ü¸®¸¦ ¿¬´Ù.
2. À¥ ¼­¹öÀÇ "µî·ÏÁ¤º¸"¸¦ ¼±ÅÃÇÑ´Ù.
3. Ȩ µð·ºÅ丮 ÅÇÀ» ¼±ÅÃÇÑ ÈÄ ÀÀ¿ë ÇÁ·Î±×·¥ ¼³Á¤¿¡¼­ ±¸¼ºÀ» Ŭ¸¯ÇÑ´Ù.
4. ÀÀ¿ë ÇÁ·Î±×·¥ ¸ÅÇÎ ÅÇ¿¡¼­ .shtml/shtm ¿Í sht ¸¦ ¼±ÅÃÇÑ ÈÄ Á¦°Å¹öưÀ» Ŭ¸¯ÇÑ´Ù.
5. È®ÀÎ ÈÄ Á¾·áÇÑ´Ù.
°ü·Ã URL CVE-2002-0072 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)