English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16052
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í BSD 4.x¿¡¼­ ÆÄ»ýµÈ ÇØ´ç FTP µ¥¸óÀº Single Byte ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Replydirname() ÇÔ¼ö¿¡ ÇÑ ¹ÙÀÌÆ®ÀÇ ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù. ·ÎÄà ¹öÆÛÀÇ Å©±â ³Ê¸Ó¿¡ NULL ¹ÙÀÌÆ®¸¦ ¾¸(Writing)À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â root ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖµµ·Ï »ç¿ëÀÚ°¡ Á¦°øÇÑ ¸®ÅÏ ÁÖ¼Ò¸¦ ¹öÆÛ¿¡ ³Ö°í ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇÑ root ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡Àº ("incoming" µð·ºÅ丮¿Í °°Àº) ¾²±â °¡´ÉÇÑ µð·ºÅ丮°¡ Á¸ÀçÇÑ´Ù¸é À͸í(anonymous) FTP¸¦ Áö¿øÇÏ´Â ½Ã½ºÅÛ»ó¿¡¼­ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ´Â µðÆúÆ®·Î ÈçÇÏ°Ô ¼³Á¤µÈ »óÅ´ ¾Æ´Ï´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2000-12/0265.html
http://www.kb.cert.org/vuls/id/593299

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NetBSD ¸ðµç ¹öÀü
OpenBSD ¸ðµç ¹öÀü
BSD ftpd 0.3.2
ÇØ°áÃ¥ OpenBSD 2.8ÀÇ °æ¿ì:
´ÙÀ½ OpenBSD º¸¾È ±Ç°í¾È 2000³â 12¿ù 18ÀÏÀÚ¸¦ Âü°íÇÏ¿© ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.openbsd.com/advisories/ftpd_replydirname.txt

NetBSDÀÇ °æ¿ì:
´ÙÀ½ NetBSD º¸¾È 2000-018À» Âü°íÇÏ¿© ±Ç°í¾È NetBSDÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://archives.neohapsis.com/archives/netbsd/2000-q4/0271.html

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2001-0053 (CVE)
°ü·Ã URL 2124 (SecurityFocus)
°ü·Ã URL 5776 (ISS)