Ãë¾àÁ¡ID |
16073 |
À§Çèµµ |
30 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç WS FTP ¼¹ö ¹öÀü¿¡ µû¸£¸é, WS FTP ¼¹ö¿¡´Â ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Ipswitch »ç¿¡¼ °³¹ßÇÑ WS FTP´Â Microsoft Windows Ç÷§Æû »ó¿¡¼ »ç¿ë °¡´ÉÇÑ FTP ¼¹öÀÌ´Ù. WS FTP 5.0.2¿Í ±× ÀÌÀü ¹öÀüµéÀº ÆÄÀÏ °æ·Î¸¦ ÆÄ½Ì(parsing)ÇÏ´Â °úÁ¤ÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿©, ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. FTP ¼¹ö¿¡ ÀÎÁõµÈ ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ ÆÄÀÏ °æ·Î¸¦ °®´Â 'cd' ¸í·ÉÀ» ÅëÇØ¼ ½Ã½ºÅÛ »óÀÇ »ç¿ë °¡´ÉÇÑ ¸ðµç CPU ÀÚ¿øÀ» ¸ðµÎ ¼Ò¸ðÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WS FTP ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Ipswitch, Inc., WS_FTP Server 5.0.2 ÀÌÇÏ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© Hotfix¸¦ ¼³Ä¡ÇÑ´Ù.
Ipswitch WS FTP Server 5.04: http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe
Ipswitch WS FTP Server 5.0.2: http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe
Ipswitch WS FTP Server 5.0.3: http://ftp1.ipswitch.com/ipswitch/product_support/ws_ftp_server/ifs504 HF1.exe |
°ü·Ã URL |
CVE-2004-1643 (CVE) |
°ü·Ã URL |
11065 (SecurityFocus) |
°ü·Ã URL |
17155 (ISS) |
|