English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12076
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Router
»ó¼¼¼³¸í ÇØ´ç Linksys WRT54G ¹«¼± ¶ó¿ìÅÍ´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Linksys WRT54G ¹«¼± ¶ó¿ìÅÍÀÇ 4.20.6 ÀÌÀü ¹öÀüµéÀº ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) 'restore.cgi' ȤÀº 'upgrade.cgi' ½ºÅ©¸³Æ®·ÎÀÇ ¾î¶² POST ¿äûÀ» ÅëÇÑ ¿µÇâÀ» ¹Þ´Â ¶ó¿ìÅ͵éÀÇ ±¸¼ºÁ¤º¸¿¡ ´ëÇÑ ´Ù¿î·Îµå ¹× ¼öÁ¤
2) root ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ¶ó¿ìÅÍ »ó¿¡¼­ ÀÓÀÇÀÇ ±â°è¾î Äڵ带 ½ÇÇà
3) ezconfig.asp¿¡ ÀÖ´Â ÀÎÁõ ¿À·ù´Â ºñÀΰ¡µÈ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Ãë¾àÇÑ Àåºñ¿¡ ±¸¼ºÁ¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ¸ç Å°°¡ ¾Ë·ÁÁ® ÀÖ´Ù¸é ±¸¼ºÁ¤º¸¸¦ ¼öÁ¤ÇÏ°Ô ÇØ ÁÙ ¼öµµ ÀÖ´Ù.
4) ¿µÇâÀ» ¹Þ´Â ¼­ºñ½ºµéÀÇ ¼º´É ÀúÇϸ¦ À¯¹ßÇÏ¿© À¥ ¼­¹ö°¡ ÀÀ´äÀÌ ¾ø´Â »óÅ·Π¸¸µé ¼ö ÀÖÀ¸¸ç ÀÌ´Â Á¤»óÀûÀÎ »ç¿ëÀڵ鿡 ´ëÇÑ ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/16806/
http://securitytracker.com/alerts/2005/Sep/1014894.html
http://www.osvdb.org/19386
http://www.osvdb.org/19387
http://www.osvdb.org/19388
http://www.osvdb.org/19389
http://www.osvdb.org/19390

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linksys WRT54G ¹«¼± ¶ó¿ìÅÍÀÇ 4.20.6 ÀÌÀü ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ Linksys Á¦Ç° ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Linksys WRT54G RouterÀÇ °¡Àå ÃֽŠÆß¿þ¾î(firmware) ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://homesupport.cisco.com/en-apac/support/routers/WRT54G/download
°ü·Ã URL CVE-2005-2799,CVE-2005-2912,CVE-2005-2914,CVE-2005-2915,CVE-2005-2916 (CVE)
°ü·Ã URL 14822 (SecurityFocus)
°ü·Ã URL 22253,22255,22259,22267 (ISS)