Ãë¾àÁ¡ID |
16081 |
À§Çèµµ |
20 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç Titan FTP ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö¿¡´Â 'LIST' ¸í·ÉÀ» ÅëÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Titan FTP ¼¹ö´Â Microsoft Windows ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ SSL (Secure Sockets Layer)À» Áö¿øÇÏ´Â FTP ¼¹öÀÌ´Ù. Titan FTP Server ¹öÀü 3.01 build 163¸¦ Æ÷ÇÔÇÑ build 169 ÀÌÀüÀÇ ¿©·¯ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚµéÀÌ "LIST -L" ¸í·ÉÀ» ÇàÇÏ´Â µ¿¾È TitanÀÌ À߸øµÈ ¼ÒÄÏ(socket)À» ¾×¼¼½ºÇÏ°Ô ÇÏ¿© ½Ã½ºÅÛÀ¸·ÎºÎÅÍÀÇ Á¢¼Ó Â÷´Ü¿¡ ÀÇÇÑ ¼ºñ½º °ÅºÎ¸¦ À¯¹ßÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Titan FTP ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: South River Technologies, Titan FTP Server 3.01 build 163 Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ South River Technologies»ç À¥ »çÀÌÆ®¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Titan FTP ¼¹öÀÇ °¡Àå ÃֽйöÀü(3.10 build 169 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.southrivertech.com/products/titanftp/index.html |
°ü·Ã URL |
CVE-2004-0437 (CVE) |
°ü·Ã URL |
10272 (SecurityFocus) |
°ü·Ã URL |
16057 (ISS) |
|