English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16067
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç WFTPD FTP ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Texas Imperial Software WFTPD´Â Microsoft Windows ¿î¿µÃ¼Á¦¿ë FTP ¼­¹öÀÌ´Ù. 3.21 R2 ÀÌÇÏÀÇ WFTPD FTP ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´Ù¾çÇÑ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οìµé°ú ¼­ºñ½º °ÅºÎ °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù:

1. µÎ °³ÀÇ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Ãë¾àÇÑ FTP ¸í·ÉµéÀº LIST, NLST, ±×¸®°í STATÀÌ´Ù. °ø°ÝÀÚ´Â ·¹Áö½ºÆ®¸®ÀÇ Secure ¿É¼ÇÀÌ 0ÀÌ ¾Æ´Ï¶ó¸é ÀÓÀÇÀÇ »ç¿ëÀÚ·Î ·Î±×ÀεǾî ÀÖ¾î¾ß ÇÑ´Ù.
2. µÎ °³ÀÇ ¼­ºñ½º °ÅºÎ °ø°ÝµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ WFTPD ¼­¹ö ÇÁ·Î¼¼½º¸¦ ÅëÇØ CPU »ç¿ëÀ²À» 100%·Î ¸¸µé ¼ö ÀÖÀ¸¸ç ¶ÇÇÑ Æ¯º°ÇÑ ¹®ÀÚ¿­À» º¸³» WFTPD¸¦ Å©·¡½¬°¡ ³ªµµ·Ï ÇÒ ¼ö ÀÖ´Ù. À̸¦ µµ¿ëÇϱâ À§Çؼ­ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â MKD³ª XMKD FTP ¸í·ÉÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/355679
http://www.securityfocus.com/archive/1/355680

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Windows Any version
Texas Imperial Software WFTPD Pro Server 3.21 Release 1 (trial) (latest version)
Texas Imperial Software WFTPD Pro Server 3.20 Release 2 (trial)
Texas Imperial Software WFTPD Server 3.21 Release 1 (trial) (latest version)
Texas Imperial Software WFTPD Server 3.10 Release 1 (trial)
ÇØ°áÃ¥ Texas Imperial Software À¥ »çÀÌÆ®ÀÎ http://www.wftpd.com ¿¡¼­ WFTPDÀÇ °¡Àå ÃֽйöÀü(3.21 R2 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-0340,CVE-2004-0341,CVE-2004-0342 (CVE)
°ü·Ã URL 9767 (SecurityFocus)
°ü·Ã URL (ISS)