English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23126
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í DameWare NT UtilitiesÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â Á¤º¸ À¯Ãâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. DameWare NT Utilities´Â ÅëÇÕµÈ NT/2000/XP/2003ÀÇ °ü¸®¸¦ À§ÇÑ µµ±¸µéÀÇ ¸ðÀ½À» Á¦°øÇÏ´Â ¿£ÅÍÇÁ¶óÀÌÁî °ü¸® ½Ã½ºÅÛ ¾ÖÇø®ÄÉÀ̼ÇÀÌ´Ù. DameWare NT Utilities 4.9 ÀÌÇÏÀÇ ¹öÀüµéÀº ·ÎÄà °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ Á¤º¸¸¦ °¡Á®°¡°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. PMDump¸¦ ÀÌ¿ëÇØ¼­ ¿ø°ÝÁöÀÇ ÄÄÇ»ÅÍ¿¡ À§Ä¡ÇÑ DNTUS26 ÇÁ·Î¼¼½ºÀÇ ¸Þ¸ð¸®¸¦ ÆÄÀÏ¿¡ ´ýÇÁ(dump)ÇÏ¸é Æò¹®À¸·Î ÀúÀåµÈ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ ¾òÀ» ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5TP0A2KFHW.html
http://www.securityfocus.com/archive/1/395987
http://securitytracker.com/alerts/2005/Apr/1013725.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
DameWare Development LLC, DameWare NT Utilities 4.9 ÀÌÇÏÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ DameWare Products Development À¥ »çÀÌÆ®ÀÎ http://www.dameware.com/downloads ¿¡¼­ ÃֽŹöÀüÀÇ DameWare Mini Remote Control(4.9 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-1166 (CVE)
°ü·Ã URL 13200 (SecurityFocus)
°ü·Ã URL 20140 (ISS)