English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22324
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 1.0.5 ȤÀº ÀÌÀüÀÇ Sami HTTP ¼­¹öÀÇ ¹öÀüÀÌ °¡µ¿ µÇ°í ÀÖ´Ù. Sami HTTP ¼­¹ö´Â Microsoft Windows ¿î¿µÃ¼Á¦ µéÀ» À§ÇÑ ¼Ò±Ô¸ðÀÇ ÀÛÀº ±â´ÉÀ» °¡Áø À¥ ¼­¹öÀÌ´Ù. Sami HTTP ¼­¹ö 1.0.5¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ´ÙÀ½ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

- µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¹®¼­ µð·ºÅ丮 ¿ÜºÎ¿¡ À§Ä¡ÇÑ ÆÄÀÏÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- ¼ö½Å µ¥ÀÌÅ͸¦ ó¸®ÇÏ´Â °úÁ¤¿¡¼­ÀÇ NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶ ¿¡·¯´Â À¥ ¼­ºñ½º¸¦ Å©·¡½¬ ½Ã۴µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç HTTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/14283
http://www.securitytracker.com/alerts/2005/Feb/1013191.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
KarjaSoft, Sami HTTP Server 1.0.5 ÀÌÇÏÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÃֽйöÀüÀÇ Sami HTTP Server·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.freenew.net/windows/sami-http-server-201/37349.htm
°ü·Ã URL CVE-2005-0450,CVE-2005-0451 (CVE)
°ü·Ã URL 12559 (SecurityFocus)
°ü·Ã URL 19338,19340 (ISS)