Ãë¾àÁ¡ID |
16055 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç FTP µ¥¸óÀº setproctitle() Format String Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Wu-ftpd, OpenBSD ftpd (ÀÌ ÆÐŰÁöÀÇ Æ÷ÆÃµéÀº ¸î¸î Linux ¹èÆ÷ÆÇ¿¡ ¹èÆ÷µÊ), HP-UX ftpd, ±×¸®°í proftpdÀÇ ¹öÀüµéÀ» Æ÷ÇÔÇÑ ´Ù¼öÀÇ FTP µ¥¸óÀº setproctitle() ÇÔ¼ö¿¡ »ç¿ëÀÚ ÀÔ·ÂÀ» °Ç³×´Â °úÁ¤ÀÌ ¿øÀÎÀÌ µÇ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Setproctitle() ÇÔ¼ö°¡ ºÒ·ÁÁú ¶§, ÇϳªÀÇ ¹öÆÛ°¡ »ý¼ºµÇ°í setproctitle ÇÔ¼ö¿¡ Format Àμö·Î Àü´ÞµÈ´Ù. ÀÌ ¹öÆÛÀÇ ³»¿ëµéÀ» Àß Á¶ÀÛÇÔÀ¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ½ºÅÃ»ó¿¡ ÀÓÀÇÀÇ °ªµéÀ» µ¤¾î¾µ ¼ö ÀÖÀ¸¸ç, À̸¦ ÅëÇØ root ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-2000-13.html http://www.kb.cert.org/vuls/id/29823 http://www.cert.org/incident_notes/IN-2000-10.html ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:35.proftpd.asc http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: BSD ftpd 5.51 ȤÀº BSD ftpd 5.60¿¡¼ ÆÄ»ýµÈ FTPD ¹öÀüµé FreeBSD Ports Collection ¸ðµç ¹öÀü HP-UX 10.xx,11.00 ProFTPD 1.2.0rc2 ÀÌÀü ¹öÀüµé wu-ftpd 2.6.0 ÀÌÇÏ |
ÇØ°áÃ¥ |
ProFTPDÀÇ °æ¿ì: ´ÙÀ½ Professional FTP Daemon ProjectÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© proftpdÀÇ °¡Àå ÃֽйöÀü (ProFTPD 1.2.0rc2)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.proftpd.org/
Wu-FTPDÀÇ °æ¿ì: ´ÙÀ½ WU-FTPD °³¹ß±×·ì À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© WU-FTPDÀÇ °¡Àå ÃֽйöÀü (2.6.1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://linux.softpedia.com/get/Internet/FTP/WU-dash-FTPD-304.shtml
NetBSDÀÇ °æ¿ì: ´ÙÀ½ NetBSD º¸¾È ±Ç°í¾È 2000-009À» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc
OpenBSDÀÇ °æ¿ì: ´ÙÀ½ OpenBSD 2000³â 7¿ù 5ÀÏÀÚ º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch
HP-UXÀÇ °æ¿ì: Hewlett-Packard»ç º¸¾È °Ô½Ã¹° HPSBUX0007-117, Sec. Vulnerability in ftpd **Rev.04** À» Âü°íÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.securityfocus.com/advisories/2404 |
°ü·Ã URL |
CVE-2000-0574 (CVE) |
°ü·Ã URL |
1425 (SecurityFocus) |
°ü·Ã URL |
4908 (ISS) |
|