English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22274
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ´ÙÀ½ Windows Ç÷§ÆûµéÀ» À§ÇÑ thttpd HTTP ¼­¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Acme Labs¿¡ ÀÇÇØ °³¹ßµÈ thttpd´Â Microsoft Windows, Unix Ç÷§ÆûµéÀ» À§ÇÑ °£´ÜÇÑ À¥ ¼­¹ö µ¥¸óÀÌ´Ù. Microsoft Windows »ó¿¡¼­ ÀÛµ¿ÇÏ´Â thttpd ¹öÀü 2.07 beta 0.4´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼­¹ö¿¡ ÀÖ´Â µð·ºÅ丮¸¦ Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ´ÙÀ½°ú °°Àº URLÀ» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â À¥ ¼­¹öÀÇ ·ÎÄà ÆÄÀÏ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î °¥ ¼ö ÀÖ´Ù:

http://[target.host]/%5c../test.ini
http://[target.host]/c:\test.ini

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/370848

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
ACME Labs, thttpd 2.07 beta 0.4
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© thttpd °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://www.acme.com/software/thttpd/
°ü·Ã URL CVE-2004-2628 (CVE)
°ü·Ã URL 10862 (SecurityFocus)
°ü·Ã URL 16882 (ISS)