English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16069
À§Çèµµ 30
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â oftpd 0.3.6 ȤÀº ÀÌÀüÀÇ ¹öÀüÀÌ °¡µ¿µÇ°í ÀÖ´Â °ÍÀ¸·Î ³ªÅ¸³­´Ù.
oftpd´Â Unix¿Í Linux ¿î¿µÃ¼Á¦¸¦ À§ÇØ ¹«·á·Î »ç¿ë °¡´ÉÇÑ FTP ¼­¹öÀÌ´Ù. oftpd ¹öÀü 0.3.6 ȤÀº ÀÌÀüÀÇ ¹öÀüµéÀº ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿µÇâÀ» ¹Þ´Â FTP ¼­¹ö°¡ 255 º¸´Ù ´õ Å« ¼ýÀÚ¸¦ °¡Áø port ¸í·ÉÀ» ¹ÞÀ» ¶§, ¼­¹ö´Â Å©·¡½¬¸¦ ÀÏÀ¸Å°°í ¼öµ¿À¸·Î Àç½ÃÀÛ½ÃÄÑ¾ß ÇÑ´Ù. port ¸í·ÉÀº ½ÉÁö¾î »ç¿ëÀÚ°¡ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ ÀÔ·ÂÇϱâ Àü¿¡µµ ³»¸± ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.time-travellers.org/oftpd/oftpd-dos.html
http://secunia.com/advisories/11220/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Shane Kerr, oftpd 0.3.6
Debian Linux 3.0
Gentoo Technologies ȍ, Gentoo Linux Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ oftpd À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ oftpd ¹öÀü(0.3.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.time-travellers.org/oftpd/

Debian/GNU Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-473-1À» ÂüÁ¶ÇÏ¿© oftpdÀÇ °¡Àå ÃֽйöÀü(0.3.6-6 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-473

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200403-08À» ÂüÁ¶ÇÏ¿© oftpdÀÇ °¡Àå ÃֽйöÀü(0.3.7 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200403-08.xml

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0376 (CVE)
°ü·Ã URL 9980 (SecurityFocus)
°ü·Ã URL 15622 (ISS)