English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16055
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç FTP µ¥¸óÀº setproctitle() Format String Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Wu-ftpd, OpenBSD ftpd (ÀÌ ÆÐŰÁöÀÇ Æ÷ÆÃµéÀº ¸î¸î Linux ¹èÆ÷ÆÇ¿¡ ¹èÆ÷µÊ), HP-UX ftpd, ±×¸®°í proftpdÀÇ ¹öÀüµéÀ» Æ÷ÇÔÇÑ ´Ù¼öÀÇ FTP µ¥¸óÀº setproctitle() ÇÔ¼ö¿¡ »ç¿ëÀÚ ÀÔ·ÂÀ» °Ç³×´Â °úÁ¤ÀÌ ¿øÀÎÀÌ µÇ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Setproctitle() ÇÔ¼ö°¡ ºÒ·ÁÁú ¶§, ÇϳªÀÇ ¹öÆÛ°¡ »ý¼ºµÇ°í setproctitle ÇÔ¼ö¿¡ Format Àμö·Î Àü´ÞµÈ´Ù. ÀÌ ¹öÆÛÀÇ ³»¿ëµéÀ» Àß Á¶ÀÛÇÔÀ¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ½ºÅÃ»ó¿¡ ÀÓÀÇÀÇ °ªµéÀ» µ¤¾î¾µ ¼ö ÀÖÀ¸¸ç, À̸¦ ÅëÇØ root ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2000-13.html
http://www.kb.cert.org/vuls/id/29823
http://www.cert.org/incident_notes/IN-2000-10.html
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:35.proftpd.asc
http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html
http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
BSD ftpd 5.51 ȤÀº BSD ftpd 5.60¿¡¼­ ÆÄ»ýµÈ FTPD ¹öÀüµé
FreeBSD Ports Collection ¸ðµç ¹öÀü
HP-UX 10.xx,11.00
ProFTPD 1.2.0rc2 ÀÌÀü ¹öÀüµé
wu-ftpd 2.6.0 ÀÌÇÏ
ÇØ°áÃ¥ ProFTPDÀÇ °æ¿ì:
´ÙÀ½ Professional FTP Daemon ProjectÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© proftpdÀÇ °¡Àå ÃֽйöÀü (ProFTPD 1.2.0rc2)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.proftpd.org/

Wu-FTPDÀÇ °æ¿ì:
´ÙÀ½ WU-FTPD °³¹ß±×·ì À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© WU-FTPDÀÇ °¡Àå ÃֽйöÀü (2.6.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://linux.softpedia.com/get/Internet/FTP/WU-dash-FTPD-304.shtml

NetBSDÀÇ °æ¿ì:
´ÙÀ½ NetBSD º¸¾È ±Ç°í¾È 2000-009À» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc

OpenBSDÀÇ °æ¿ì:
´ÙÀ½ OpenBSD 2000³â 7¿ù 5ÀÏÀÚ º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch

HP-UXÀÇ °æ¿ì:
Hewlett-Packard»ç º¸¾È °Ô½Ã¹° HPSBUX0007-117, Sec. Vulnerability in ftpd **Rev.04** À» Âü°íÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.securityfocus.com/advisories/2404
°ü·Ã URL CVE-2000-0574 (CVE)
°ü·Ã URL 1425 (SecurityFocus)
°ü·Ã URL 4908 (ISS)