English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12086
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Easy File Sharing À¥ ¼­¹ö´Â ¹öÀü 3.2¿¡ Á¸ÀçÇÏ´Â Format String Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Easy File Sharing À¥ ¼­¹ö´Â ¹æ¹®ÀÚµéÀÌ IE, Mozilla, Netscape°ú °°Àº À¥ ºê¶ó¿ìÀú¸¦ ÅëÇÏ¿© ½±°Ô ÆÄÀϵéÀ» ¾÷·Îµå ¹× ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÄÀÏ °øÀ¯ ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Easy File Sharing Web Server ¹öÀü 3.2¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ·Î±ë ¼³ºñ¿¡ ÀÖ´Â Format String Ãë¾àÁ¡¿¡ Ãë¾àÇϸç HTTP GET ¿äû¿¡¼­ ÁúÀÇ ¹®ÀÚ¿­ Àμö¿¡ Format String Áö½ÃÀÚµéÀ» ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. Ãß°¡ÀûÀ¸·Î ÀÌ ¾îÇø®ÄÉÀ̼ÇÀº Cross-Site Scripting°ú ÀÓÀÇÀÇ ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ÄíÅ° ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª Windows ½ÃÀÛ Æú´õ¿¡ ¾ÇÀÇÀûÀÎ ÆÄÀÏÀ» ¾÷·ÎµåÇÔÀ¸·Î½á ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/427158/30/0/threaded
http://secunia.com/advisories/19178/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Enterprise IT Planet, Easy File Sharing Web Server 3.2
Microsoft Windows Any version
ÇØ°áÃ¥ Easy File Sharing À¥ ¼­¹ö ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.sharing-file.com/download.htm ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Easy File Sharing À¥ ¼­¹öÀÇ °¡Àå ÃֽŠ¹öÀü(3.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-1159,CVE-2006-1160,CVE-2006-1161 (CVE)
°ü·Ã URL 17046 (SecurityFocus)
°ü·Ã URL 25135,25136 (ISS)