English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21051
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç MS FrontPageÀÇ Image MapperÀÎ htimage.exe CGI´Â ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
FrontPage¿¡ Æ÷ÇÔµÈ htimage.exe¿Í imagemap.exe ÆÄÀϵéÀº ¼­¹ö »çÀ̵忡¼­ À̹ÌÁö ¸ÅÇÎ ±â´ÉÀÇ Ã³¸®¸¦ ´ã´çÇÑ´Ù. Á¤»óÀûÀÎ ÀÛµ¿ »óȲ¿¡¼­´Â http://target/path/htimage.exe/mapname?x,y ÇüÅÂÀÇ ¸Ê(map) À̸§°ú ÇÑ ¼ÂÀÇ ÁÂÇ¥°¡ Àü´ÞµÈ´Ù.
741°³ ÀÌ»óÀÇ mapnameÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç, À¥ »ç¿ëÀÚÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö¿¡ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/1117
http://www.iss.net/security_center/static/4484.php

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Microsoft FrontPage Server Extensions 97
Microsoft FrontPage Server Extensions 98
Microsoft Personal Web Server 4.0
Microsoft Windows Any version

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS00-28¿¡¼­ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® »ç°¡ ±Ç°íÇÑ °Íó·³ À¥¼­¹ö·ÎºÎÅÍ htimage.exe¿Í imagemap.exe ÆÄÀϵéÀ» ã¾Æ¼­ »èÁ¦ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms00-028.asp

ÀÌ Àӽà Á¶Ä¡¹æ¹ýÀº ºê¶ó¿ìÀú¿¡¼­ ¼­¹ö»ó¿¡ ÀÖ´Â À̹ÌÁö ¸ÊµéÀ» ¾×¼¼½ºÇÏÁö ¸øÇÏ°Ô ÇÏ¿© ¼­¹ö »çÀ̵忡¼­ÀÇ À̹ÌÁö ¸ÅÇÎ ±â´ÉÀ» ÁßÁö½ÃŰ´Â °ÍÀÌ´Ù. ÀÌ ÆÄÀϵ鿡 ÀÇÇØ Á¦°øµÇ´Â ±â´ÉÀº À̹ÌÁö ¸ÊµéÀ» ½º½º·Î ó¸®ÇÒ ¼ö ÀÖ´Â ´É·ÂÀ» °¡Áö°í ÀÖ´Â ÇöÀçÀÇ ºê¶ó¿ìÀúµé¿¡¼­´Â ´õ ÀÌ»ó ÇÊ¿äÇÏÁö ¾Ê´Ù.
°ü·Ã URL CVE-2000-0256 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)