| Ãë¾àÁ¡ID |
16007 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
ÇØ´ç wu-ftpd ¼¹ö´Â SITE NEWER ¸í·ÉÀ» ÅëÇÑ ÀÚ¿ø°í°¥ Ãë¾àÁ¡¿¡ Ãë¾àÇÒ ¼ö ÀÖ´Ù. Wu-ftpd´Â ÆÄÀÏÀü¼Û±Ô¾à (FTP) ¼ºñ½ºµéÀ» Á¦°øÇϴµ¥ »ç¿ëµÇ´Â ÀϹÝÀûÀÎ ÆÐŰÁöÀÌ´Ù. SITE NEWER ¸í·ÉÀº ¹Ì·¯¸µ(mirroring) ¼ÒÇÁÆ®¿þ¾î¸¦ À§ÇØ °í¾ÈµÈ wu-ftpdÀÇ Æ¯º°ÇÑ ±â´ÉÀ¸·Î Á¦½ÃÇÑ ³¯Â¥º¸´Ù ´õ ÃÖ½ÅÀÇ ÆÄÀÏ ¸ðµÎ¸¦ ÆÄ¾ÇÇϴµ¥ »ç¿ëµÈ´Ù. ¸î¸î wu-ftpd ¼¹öµéÀº °ø°ÝÀÚ°¡ ÀÌ ¸í·ÉÀ» ½ÇÇà½ÃÄÑ ¼¹ö»óÀÇ ¸ðµç °¡¿ë ¸Þ¸ð¸®¸¦ »ç¿ëÇÏ°Ô ÇÔÀ¸·Î½á ¼¹ö°¡ ÀÚ¿ø°í°¥¿¡ ºüÁú ¼ö ÀÖ´Ù. ƯÁ¤ FTP ¼¹ö¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Â ·ÎÄðú ¿ø°ÝÀÇ °ø°ÝÀÚµéÀº ´Ù·®ÀÇ ¸Þ¸ð¸®¸¦ ¼Ò¸ð½ÃÄÑ Á¤»óÀûÀÎ ½Ã½ºÅÛ ÀÛµ¿ÀÌ ¹æÇع޵µ·Ï ÇÒ ¼ö ÀÖ´Ù. ¸¸¾à ±× °ø°ÝÀÚµéÀÌ ½Ã½ºÅÛ»ó¿¡ ÆÄÀÏÀ» »ý¼ºÇÒ ¼ö¸¸ ÀÖ´Ù¸é ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ftpd µ¥¸óÀÇ ±ÇÇÑ, ´ë°³´Â rootÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.
* Ãë¾àÇÑ Ç÷§Æû: wu-ftpd 2.6.0ÀÇ ÀÌÀü ¹öÀüµé
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/3376.php http://www.cert.org/advisories/CA-1999-13.html |
| ÇØ°áÃ¥ |
´ÙÀ½ CERT ±Ç°í¾È CA-1999-13À» ÂüÁ¶ÇÏ¿© wu-ftpdÀÇ °¡Àå ÃֽŹöÀü (2.6.0 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cert.org/advisories/CA-1999-13.html |
| °ü·Ã URL |
CVE-1999-0880 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|