Ãë¾àÁ¡ID |
16074 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç WU-FTPD ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é, ¼¹ö¿¡´Â µð¹ö±× ¸ðµå·Î °¡µ¿ ÁßÀÏ ¶§ Format String Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. WU-FTPD 2.6.1 ÀÌÇÏ ¹öÀüµé¿¡´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ WU-FTPD°¡ µð¹ö±× ¸ðµå·Î ¼öÇà ÁßÀÏ ¶§ Format String Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. µð¹ö±× ¸ðµå·Î ¼öÇà ÁßÀÏ ¶§ Wu-ftpd´Â ¾ÈÀüÇÏÁö ¾ÊÀº ¹æ¹ýÀ¸·Î syslog·Î »ç¿ëÀÚ ÇàÀ§¸¦ ·Î±ëÇÑ´Ù. ¼¹öÀÇ È£½ºÆ®¸í Resolving(DNS Lookup) ¼³ºñ¿¡ ´ëÇÑ Á¦¾î±ÇÀ» °¡Áö°í ÀÖ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ¿ø°ÝÀ¸·Î root ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WU-FTP ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-2001-33.html http://www.kb.cert.org/vuls/id/639760
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Washington University, wu-ftpd 2.6.1 ÀÌÇÏ ¹öÀüµé Unix Any version Linux Any version |
ÇØ°áÃ¥ |
Debian Linux 2.2 (alias potato)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-016-3À» ÂüÁ¶ÇÏ¿© wu-ftpdÀÇ °¡Àå ÃֽйöÀü(2.6.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2001/dsa-016
HP-UX 11.00 ±×¸®°í 11.11ÀÇ °æ¿ì: ´ÙÀ½ Hewlett-Packard Company Security Bulletin HPSBUX0201-180À» ÂüÁ¶ÇÏ¿© wu-ftpdÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://online.securityfocus.com/advisories/3812
±âŸ: WU-FTPD´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2001-0187 (CVE) |
°ü·Ã URL |
2296 (SecurityFocus) |
°ü·Ã URL |
6020 (ISS) |
|