English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16053
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç HP-UX ftpd´Â glob() È®Àå¿¡ ÀÖ´Â STAT ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
ÈÞ·¿ ÆÐÄ¿µå»çÀÇ HP-UX ftpd 11.04 ÀÌÇÏ ¹öÀüµéÀº ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ ¿À¹öÇ÷οì´Â STAT ¸í·ÉÀÌ glob()¿¡ ÀÇÇØ ó¸®µÇ¾î ¸Å¿ì ±ä ¹®ÀÚ¿­·Î È®ÀåµÇ´Â ÀμöµéÀ» ¹ÞÀ» ¶§ ¹ß»ýÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ãë¾àÇÑ È£½ºÆ®»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§Çؼ­ °ø°ÝÀÚ´Â ´ë»ó È£½ºÆ®»ó¿¡ µð·ºÅ丮µéÀ» »ý¼ºÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2001-07.html
http://www.securityfocus.com/advisories/3456

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
HP-UX 10.01, 10.10, 10.20, 11.00
HP-UX 10.24 (VVOS), 11.04 (VVOS)
ÇØ°áÃ¥ ´ÙÀ½ ÈÞ·¿ ÆÐÄ¿µåÀÇ À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://itrc.hp.com

HP HP-UX 10.01: HP Patch PHNE_23947
HP HP-UX 10.10: HP Patch PHNE_23947
HP HP-UX 10.20: HP Patch PHNE_23948
HP HP-UX (VVOS) 10.24: HP Patch PHNE_24394
HP HP-UX 11.00: HP Patch PHNE_23949
HP HP-UX (VVOS) 11.0.4: HP Patch PHNE_24395

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î ÆÐÄ¡¸¦ Àû¿ëÇϱâ Àü±îÁö FTP ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ÇÏ¿©¾ß ÇÑ´Ù. À̰ÍÀÌ ¾î·Á¿ì¸é ¼­ºñ½º¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Á¦ÇÑÇÑ´Ù. À͸í(anonymous) »ç¿ëÀÚµéÀÌ ¾î¶² µð·ºÅ丮µéÀ» »ý¼ºÇϰųª ȤÀº ¾²±â°¡ °¡´ÉÇϵµ·Ï ÇØ Á־´Â ¾ÈµÈ´Ù.
°ü·Ã URL CVE-2001-0248 (CVE)
°ü·Ã URL 2552 (SecurityFocus)
°ü·Ã URL 6332 (ISS)