Ãë¾àÁ¡ID |
16046 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç BFTPD µ¥¸óÀº SITE CHOWN ¸í·ÉÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Max-Wilhelm Bruker's FTP ¼¹öÀÎ BFTPD µ¥¸óÀº Linux, BSD/OS, FreeBSD, DG-UN, Tru64 »ó¿¡¼ inetd µ¥¸ó¿¡ Á¾¼ÓµÇ¾î ¶Ç´Â µ¶¸³ÀûÀ¸·Î µ¿ÀÛÇÒ ¼ö ÀÖ´Â FTP ¼¹ö ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ BFTPD Áß 1.0.13 ¹öÀüÀº »ç¿ëÀÚ¿¡ ÀÇÇØ Á¤ÀÇµÈ ÀԷµéÀ» ÀûÀýÈ÷ ó¸®ÇÏÁö ¸øÇÏ´Â µ¥¿¡ ¿øÀÎÀÌ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow) Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ SITE CHOWN ¸í·É¾î ´ÙÀ½¿¡ Á¤ÇØÁø ÀÔ·Â ¹öÆÛÀÇ ÃÖ´ë ±æÀ̸¦ ÃʰúÇÏ´Â ¹®ÀÚ¿À» µ¡ºÙ¿© ¼¹ö¿¡ Àü´ÞÇÒ ¼ö ÀÖ´Ù.
SITE CHOWN AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA A
ÀÌ¿Í °°Àº ÇàÀ§´Â ¼¹ö »óÀÇ ¸Þ¸ð¸® ½ºÅÃ(stack)À» ¿À¹öÇ÷οì(Overflow)½ÃÄÑ °£´ÜÇÏ°Ô ¼¹ö°¡ ¼ºñ½º °ÅºÎ(Denial of Service) »óÅ¿¡ À̸£°Ô ÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ, ¼¹ö »ó¿¡¼ ·çÆ® ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖµµ·Ï ¸®ÅÏ ÁÖ¼Ò°ª(return address) À» µ¤¾î¾¸(overwrite)À¸·Î½á ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/2120 http://www.iss.net/security_center/static/5775.php
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: BSD ¸ðµç ¹öÀü DG/UX ¸ðµç ¹öÀü FreeBSD ¸ðµç ¹öÀü Linux ¸ðµç ¹öÀü Solaris ¸ðµç ¹öÀü Tru64 UNIX ¸ðµç ¹öÀü bftpd 1.0.13 |
ÇØ°áÃ¥ |
´ÙÀ½ BFTD À¥»çÀÌÆ®·ÎºÎÅÍ °¡Àå ÃֽйöÀü (BFTPD 1.0.23 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://bftpd.sourceforge.net/
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â ¼¹ö »ó¿¡¼ SITE ¸í·ÉÀ» »ç¿ëÇÒ ¼ö ¾øµµ·Ï ȯ°æ¼³Á¤ ÆÄÀÏ /etc/bftpd.conf ¿¡¼ "ENABLE_SITE" ¿£Æ®¸®¸¦ "yes" °¡ ¾Æ´Ñ "no"·Î º¯°æÇØ¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2001-0065 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|