English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16068
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç WU-FTPD FTP ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â 'chmod' ¿Í S/Key Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
WU-FTPD (Washington University FTP daemon)´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ BSD FTP µ¥¸ó¿¡ ±â¹ÝÀ» µÐ FTP ¼­¹öÀÌ´Ù. WU-FTPD 2.6.2 ÀÌÇÏ ¹öÀüµéÀº ¾Æ·¡ µÎ °¡Áö Ãë¾àÁ¡µéÀÌ Ãë¾àÇÏ´Ù:

1. 'chmod' ¸í·É - WU-FTPD¿¡ ÀÇÇØ Áö¿øµÇ´Â "restricted-gid home" ±â´ÉÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ» ¶§, Àΰ¡¹ÞÁö ¾ÊÀº »ç¿ëÀÚ°¡ ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© ¼³Á¤µÈ Ȩ µð·ºÅ丮¸¦ ¿ìȸÇÒ ¼ö ÀÖ´Ù.
2. S/Key login ó¸® - S/Key ÀÎÁõÀ» ÀÌ¿ëÇÏ´Â ¼­¹öµé »ó¿¡¼­ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ã۰í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/11055/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Washington University wu-ftpd 2.6.2 ÀÌÇÏ
Red Hat Advanced Workstation 2.1
Red Hat Enterprise Linux 2.1AS
Red Hat Enterprise Linux 2.1ES
Debian Linux 3.0
Linux Any version
ÇØ°áÃ¥ Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-457-1À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ wu-ftpd ÆÐŰÁö(2.6.2-3woody4 or later)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-457

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2004:096-09¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ wu-ftpd ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-096.html

±âŸ:
WU-FTPD´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2004-0148 (CVE)
°ü·Ã URL 9832 (SecurityFocus)
°ü·Ã URL 15423 (ISS)