English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12048
À§Çèµµ 40
Æ÷Æ® 2301
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Compaq Insight Manager HTTP ¼­¹ö´Â Format String Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Compaq Insight Manager´Â Compaq ¼­¹öµéÀ» À§ÇÑ À¥ ±â¹ÝÀÇ °ü¸® ±â´ÉÀ» Á¦°øÇØ ÁÖ´Â ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÌ´Ù. ¼­¹öµéÀ» À§ÇÑ Compaq À¥ ±â¹Ý °ü¸® Agent´Â ¸ðµç °ü¸®¹Þ´Â ÇÏÀ§ ½Ã½ºÅ۵鿡 ´ëÇÑ ÀåÄ¡ Á¤º¸¿Í SNMP Æ®·¦(traq)µéÀ» À§ÇÑ ¾ó·¯Æ®(alert)µéÀ» Á¦°øÇØ ÁØ´Ù.
Compaq Insight Manager ¹öÀü 5.00 H ±×¸®°í ÀÌÇÏ ¹öÀüµéÀº Format String °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Format StringµéÀ» Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ HTTP GET DebugSearchPaths ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â LocalSystem ±ÇÇÑÀ¸·Î Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ÄÚµåµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Compaq Insight Manager HTTP ¼­¹ö´Â ÀÌ Á¡°ËÇ׸ñ¿¡ ÀÇÇØ Å©·¡½¬ µÇ¾úÀ» ¼ö ÀÖ´Ù. ±â´ÉÀ» Á¤»óÀ¸·Î ȸº¹Çϱâ À§Çؼ­´Â ¼­ºñ½º¸¦ Àç½ÃÀÛÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5HP0J00AUU.html
http://archives.neohapsis.com/archives/fulldisclosure/2003-q3/1373.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Compaq Insight Manager 5.00 H ÀÌÇÏ ¹öÀüµé
Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç·Î½á´Â ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ³ª¿ÍÀÖÁö ¾Ê´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á Web-Enabled Agent¸¦ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. Web-Enabled Agent¸¦ ÀÛµ¿ÁßÁö ½Ã´Â ¹æ¹ý¿¡ ´ëÇØ¼­´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ "Disabling the Web-Enabled Agents"¿¡ ÀÖ´Â ¹®¼­¸¦ Âü°íÇÏ¾ß ÇÑ´Ù:
http://h18013.www1.hp.com/products/servers/management/security.html
°ü·Ã URL (CVE)
°ü·Ã URL 8336 (SecurityFocus)
°ü·Ã URL 12823 (ISS)