English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12020
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç WFTPD µ¥¸óÀº MKD¿Í CWD ¸í·ÉµéÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
WFTPD µ¥¸óÀº Windows NT/2000/XP »ó¿¡¼­ µ¿ÀÛÇϵµ·Ï Á¦ÀÛµÈ, ÇöÀç ³Î¸® ÀÌ¿ëµÇ°í Àִ ǥÁØ FTP ¼­ºñ½ºÀÌ´Ù. WFTD µ¥¸óÀÇ ÀϺΠ¹öÀüµé¿¡´Â ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Â µ¥, ÀÌ ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow)´Â ¿ø°ÝÁö °ø°ÝÀÚ°¡ ´ÙÀ½°ú °°ÀÌ 255 ¹®ÀÚ ÀÌ»óÀÇ ±ä ÀÎÀÚ¸¦ °®´Â MKD¿Í CWD¸¦ °áÇÕÇÏ¿© ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù.

MKD aaaaa¡¦['a'*300]¡¦aaaaaaaa
CWD aaaaa¡¦['a'*300]...aaaaaaaa

ÀÌ·¯ÇÑ ¸í·ÉÀº FTP ¼­¹ö »ó¿¡¼­ ¹öÆÛ¸¦ ¿À¹ö·±(overrun) ½Ã۰í Á¤»óÀûÀÎ ¼­ºñ½º°¡ ºÒ°¡´ÉÇϵµ·Ï ¼­ºñ½º °ÅºÎ(Denial of Service) »óÅ¿¡ À̸£°Ô ÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ, ÃÖ¾ÇÀÇ °æ¿ì¿¡´Â ¼­¹ö¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¸ç ¼­¹ö »ó¿¡¼­ ÀÓÀÇÀÇ ÄÚµå ½ÇÇ൵ °¡´ÉÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/747
http://www.iss.net/security_center/static/3417.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æûµé :
Texas Imperial Software WFTPD 2.34
Texas Imperial Software WFTPD 2.40
Texas Imperial Software WFTPD 3.0
ÇØ°áÃ¥ »ç¿ëÀÚ ±ÇÇÑÀ» Ȩ µð·ºÅ丮¿Í ±× ÀÌÇÏ·Î Á¦ÇÑÇÏ¿©¾ß ÇÑ´Ù.

1. ¸Þ´º¿¡¼­ Security ¡æ User Rights À» ¿¬´Ù
2. »ç¿ëÀÚ¸íÀ» "anonymous" ³ª ÇØ´ç »ç¿ëÀÚ·Î ¼±ÅÃÇÑ´Ù.
3. User/Rights Security Dialog À©µµ¿ìÁî »ó¿¡¼­ "Restrict To Home Directory And Below" ¸¦ üũÇÑ´Ù.

-- ¶Ç´Â --

Texas Imperial Software À¥ ÆäÀÌÁö http://www.wftpd.com/ ¸¦ Âü°íÇÏ¿© WFTPD 3.0R3 ³ª ±× ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-1999-0950 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)