Ãë¾àÁ¡ID |
16052 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
BSD 4.x¿¡¼ ÆÄ»ýµÈ ÇØ´ç FTP µ¥¸óÀº Single Byte ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Replydirname() ÇÔ¼ö¿¡ ÇÑ ¹ÙÀÌÆ®ÀÇ ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù. ·ÎÄà ¹öÆÛÀÇ Å©±â ³Ê¸Ó¿¡ NULL ¹ÙÀÌÆ®¸¦ ¾¸(Writing)À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â root ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖµµ·Ï »ç¿ëÀÚ°¡ Á¦°øÇÑ ¸®ÅÏ ÁÖ¼Ò¸¦ ¹öÆÛ¿¡ ³Ö°í ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇÑ root ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ("incoming" µð·ºÅ丮¿Í °°Àº) ¾²±â °¡´ÉÇÑ µð·ºÅ丮°¡ Á¸ÀçÇÑ´Ù¸é À͸í(anonymous) FTP¸¦ Áö¿øÇÏ´Â ½Ã½ºÅÛ»ó¿¡¼ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ´Â µðÆúÆ®·Î ÈçÇÏ°Ô ¼³Á¤µÈ »óÅ´ ¾Æ´Ï´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2000-12/0265.html http://www.kb.cert.org/vuls/id/593299
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: NetBSD ¸ðµç ¹öÀü OpenBSD ¸ðµç ¹öÀü BSD ftpd 0.3.2 |
ÇØ°áÃ¥ |
OpenBSD 2.8ÀÇ °æ¿ì: ´ÙÀ½ OpenBSD º¸¾È ±Ç°í¾È 2000³â 12¿ù 18ÀÏÀÚ¸¦ Âü°íÇÏ¿© ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.openbsd.com/advisories/ftpd_replydirname.txt
NetBSDÀÇ °æ¿ì: ´ÙÀ½ NetBSD º¸¾È 2000-018À» Âü°íÇÏ¿© ±Ç°í¾È NetBSDÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://archives.neohapsis.com/archives/netbsd/2000-q4/0271.html
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2001-0053 (CVE) |
°ü·Ã URL |
2124 (SecurityFocus) |
°ü·Ã URL |
5776 (ISS) |
|