Ãë¾àÁ¡ID |
12078 |
À§Çèµµ |
40 |
Æ÷Æ® |
69 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
TFTP |
»ó¼¼¼³¸í |
ÇØ´ç TFTP ¼¹ö´Â ¾ÆÁÖ ±ä ÆÄÀÏ À̸§À» ÅëÇÑ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. TFTP(Trivial File Transfer Protocol)´Â ³×Æ®¿öÅ©·Î Á¢¼ÓµÈ Àåºñµé »çÀÌ¿¡ ÀÎÁõÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê°í ½±°Ô ÆÄÀϵéÀÇ Àü¼ÛÀ» °¡´ÉÇÏ°Ô ÇØ ÁÖ´Â ÇÁ·ÎÅäÄÝÀÌ´Ù. ¸î¸î TFTP ¼¹öµéÀº ¹öÆÛ ¿À¹öÇ÷οì·Î ÀÎÇÑ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. 1000 ȤÀº ±× ÀÌ»óÀÇ ¹®ÀÚµé·Î µÈ ÆÄÀϸíÀ» Æ÷ÇÔÇÑ RRQ(Read Request, Àб⠿äû)À» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ¼¹ö¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2002-07/0352.html http://archives.neohapsis.com/archives/bugtraq/2003-06/0056.html http://archives.neohapsis.com/archives/bugtraq/2003-06/0032.html http://www.debian.org/security/2003/dsa-314 http://www.linuxsecurity.com/content/view/105077/104/ http://www.securiteam.com/exploits/5ZP0E0AAAU.html http://www.cisco.com/warp/public/707/ios-tftp-long-filename-pub.shtml
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ¸ðµç TFTP ¼¹ö ¸ðµç ¹öÀü ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ¿µÇâÀ» ¹Þ´Â TFTP ¼¹ö¸¦ »ç¿ë ÁßÁöÇÏ¿©¾ß ÇÑ´Ù. ±×·¸Áö ¾ÊÀ¸¸é Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2002-0813,CVE-2003-0380 (CVE) |
°ü·Ã URL |
401,5328,7819 (SecurityFocus) |
°ü·Ã URL |
9700,12192 (ISS) |
|