English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29079
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Check Point Firewall-1 HTTP Security ¼­¹ö´Â ´ÙÁßÀÇ Format String Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Format String Áö½ÃÀÚµéÀÌ ¿¡·¯ ¸Þ½ÃÁö¿¡¼­ »ç¿ëµÇ¾î Áöµµ·Ï ÇÑ HTTP ¿äûµéÀ» ÅëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µé ÁßÀÇ Çϳª¸¦ µµ¿ëÇÏ¿© °ü¸®ÀÚÀÇ ±ÇÇÑÀÎ "SYSTEM" À̳ª "root"ÀÇ ±ÇÇÑÀ¸·Î ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Check Point Software Next Generation FP3 HF2
Check Point Software Next Generation FP3 HF1
Check Point Software Next Generation FP3
Check Point Software Next Generation FP2
Check Point Software Next Generation FP1
Check Point Software Next Generation
Check Point Software NG-AI R55
Check Point Software NG-AI R54
Check Point Software NG-AI

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/790771

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Check Point Firewall
ÇØ°áÃ¥ üũ Æ÷ÀÎÆ® »ç´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ Fix¸¦ ¸¸µé¾î ³õ¾Ò´Ù. À¯Áöº¸¼ö °è¾àÀ» ü°áÇÑ °í°´µéÀº üũ Æ÷ÀÎÆ® À¯Áöº¸¼ö ä³ÎµéÀ» ÅëÇØ Fix¸¦ ±¸ÇÒ ¼ö ÀÖ´Ù. ÀÚ¼¼ÇÑ ³»¿ë¿¡ ´ëÇØ¼­´Â ´ÙÀ½ üũ Æ÷ÀÎÆ® »ç º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿©¾ß ÇÑ´Ù:
http://www.checkpoint.com/techsupport/downloads/docs/firewall1/FW-1_SS_Hotfix_RNs.pdf

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â ÇÊ¿äÇÏÁö ¾Ê´Ù¸é HTTP Security ServerµéÀ̳ª Application Intelligence component¸¦ »ç¿ëÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-0039 (CVE)
°ü·Ã URL 9581 (SecurityFocus)
°ü·Ã URL 14149 (ISS)