English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16018
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç FTP µ¥¸óÀº 'site exec' ¸í·É¿¡ Format String Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº "site exec" ¸í·É¾î¸¦ ½ÇÇàÇÏ´Â °úÁ¤¿¡¼­ Àß Á¶ÀÛµÈ ¹®ÀÚ Format StringµéÀ» °Ç³ÛÀ¸·Î½á FTP ¼­ºñ½º°¡ °ÅºÎµÇ°Ô Çϰųª »ðÀÔµÈ ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÇµµ·Ï Segmentation ViolationÀ» ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù.
ÀÓÀÇÀÇ °èÁ¤À¸·Î ·Î±×ÀÎÇÑ ÈÄ ´ÙÀ½°ú °°Àº ¿äûÀ» º¸³¿À¸·Î½á FTP Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© FTP µ¥¸óÀ» Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù:

ftp> quote site exec %n %n %n %n %n %n %n
Connection closed by foreign host

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Wu-ftpd 2.6.0 ÀÌÇÏ
OpenBSD ftpd 6.4 ÀÌÇÏ
FreeBSD Ports Collection ¸ðµç ¹öÀü
HP-UX 10.xx ±×¸®°í 11.0x
ProFTPD 1.2.0rc2 ¹Ì¸¸
BSD ftpd 5.51 ȤÀº BSD ftpd 5.60 (¸¶Áö¸· BSD ¸±¸®Áî)¿¡¼­ À¯·¡µÈ FTPD¸¦ °¡µ¿ÇÏ´Â ½Ã½ºÅÛ

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2000-13.html
ÇØ°áÃ¥ ProFTPDÀÇ °æ¿ì:
´ÙÀ½ "The Professional FTP Daemon Project"ÀÇ À¥»çÀÌÆ®·ÎºÎÅÍ proftpdÀÇ °¡Àå ÃֽŹöÀü (ProFTPD 1.2.7)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.proftpd.org/download.html

WU-FTPDÀÇ °æ¿ì:
´ÙÀ½ WU-FTPD Development Group À¥»çÀÌÆ®·ÎºÎÅÍ WU-FTPDÀÇ °¡Àå ÃֽŹöÀü (2.6.2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://linux.softpedia.com/get/Internet/FTP/WU-dash-FTPD-304.shtml

OpenBSDÀÇ °æ¿ì:
OpenBSD 2000³â 7¿ù 5ÀÏÀÚ º¸¾È ±Ç°í¾ÈÀ» Âü°íÇÏ¿© 019_ftpd.patch ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/019_ftpd.patch

NetBSDÀÇ °æ¿ì:
´ÙÀ½ NetBSD º¸¾È ±Ç°í¾È 2000-009À» Âü°íÇÏ¿© ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc

FreeBSDÀÇ °æ¿ì:
´ÙÀ½ º¸¾È ±Ç°í¾È FreeBSD-SA-00:35À» Âü°íÇÏ¿© ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:35.proftpd.asc

HP-UXÀÇ °æ¿ì:
´ÙÀ½ HP IT Resource Center ÆäÀÌÁö¸¦ Âü°íÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡ (Rev.03)¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://us-support.external.hp.com
For HP-UX release 11.00 PHNE_21936,
HP-UX release 11.04 PHNE_22060,
HP-UX release 10.20 PHNE_22057,
HP-UX release 10.24 PHNE_22059,
HP-UX release 10.01 and 10.10 PHNE_22058.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)