Ãë¾àÁ¡ID |
16067 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç WFTPD FTP ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Texas Imperial Software WFTPD´Â Microsoft Windows ¿î¿µÃ¼Á¦¿ë FTP ¼¹öÀÌ´Ù. 3.21 R2 ÀÌÇÏÀÇ WFTPD FTP ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´Ù¾çÇÑ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οìµé°ú ¼ºñ½º °ÅºÎ °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù:
1. µÎ °³ÀÇ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Ãë¾àÇÑ FTP ¸í·ÉµéÀº LIST, NLST, ±×¸®°í STATÀÌ´Ù. °ø°ÝÀÚ´Â ·¹Áö½ºÆ®¸®ÀÇ Secure ¿É¼ÇÀÌ 0ÀÌ ¾Æ´Ï¶ó¸é ÀÓÀÇÀÇ »ç¿ëÀÚ·Î ·Î±×ÀεǾî ÀÖ¾î¾ß ÇÑ´Ù. 2. µÎ °³ÀÇ ¼ºñ½º °ÅºÎ °ø°ÝµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ WFTPD ¼¹ö ÇÁ·Î¼¼½º¸¦ ÅëÇØ CPU »ç¿ëÀ²À» 100%·Î ¸¸µé ¼ö ÀÖÀ¸¸ç ¶ÇÇÑ Æ¯º°ÇÑ ¹®ÀÚ¿À» º¸³» WFTPD¸¦ Å©·¡½¬°¡ ³ªµµ·Ï ÇÒ ¼ö ÀÖ´Ù. À̸¦ µµ¿ëÇϱâ À§Çؼ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â MKD³ª XMKD FTP ¸í·ÉÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/355679 http://www.securityfocus.com/archive/1/355680
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Windows Any version Texas Imperial Software WFTPD Pro Server 3.21 Release 1 (trial) (latest version) Texas Imperial Software WFTPD Pro Server 3.20 Release 2 (trial) Texas Imperial Software WFTPD Server 3.21 Release 1 (trial) (latest version) Texas Imperial Software WFTPD Server 3.10 Release 1 (trial) |
ÇØ°áÃ¥ |
Texas Imperial Software À¥ »çÀÌÆ®ÀÎ http://www.wftpd.com ¿¡¼ WFTPDÀÇ °¡Àå ÃֽйöÀü(3.21 R2 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-0340,CVE-2004-0341,CVE-2004-0342 (CVE) |
°ü·Ã URL |
9767 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|