| Ãë¾àÁ¡ID |
16021 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
Solaris ¿î¿µÃ¼Á¦¿¡ Æ÷ÇÔµÈ ftp ¼¹ö¿¡ ÀÖ´Â ¹®Á¦Á¡Àº local »ç¿ëÀÚ¿¡°Ô ¾ÏÈ£ÈµÈ ÆÐ½º¿öµåµéÀ» °¡Áö°í ÀÖ´Â shadow ÆÄÀÏÀÇ ºÎºÐµéÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Glob() ÇÔ¼öÀÇ ¹öÆÛ ¿À¹öÇ÷οì¿Í °ü·ÃµÈ ¹®Á¦ ¶§¹®¿¡ SolarisÀÇ ftp ¼¹ö¿¡ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ °úÁ¤¿¡¼ shadow ÆÄÀÏÀÇ ºÎºÐµéÀ» core ÆÄÀÏ·Î dump ½ÃŲ´Ù. À̰ÍÀº 'CWD ~' ¸í·ÉÀ¸·Î °£´ÜÇÏ°Ô ÇàÇÒ ¼ö ÀÖ´Ù. µû¶ó¼ local »ç¿ëÀÚ´Â ftp ¼¹ö¿¡ ¹öÆÛ ¿À¹öÇ÷ο츦 À¯¹ß½Ã۰í core ÆÄÀÏÀÌ ¸ðµÎ Àбâ·Î µÇ¾î Àֱ⠶§¹®¿¡ ¼¹ö¿¡ ÀÖ´Â shadow ÆÄÀÏÀÇ ºÎºÐÀ» ¾òÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2001-04/0285.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Solaris 2.5, 2.5.1, 2.6, 7, 8 |
| ÇØ°áÃ¥ |
Vender¿Í »óÀÇÇÏ¿© ÇØ´ç OS¿¡ ¸Â´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
Solaris 5: 103577-13 Solaris 5 x86: 103578-13 Solaris 5.1: 103603-16 Solaris 5.1 x86: 103604-16 Solaris 6: 106301-04 Solaris 6 x86: 106302-04 Solaris 7: 110646-03 Solaris 7 x86: 110647-03 Solaris 8: 111606-02 Solaris 8 x86: 111607-02 |
| °ü·Ã URL |
CVE-2001-0421 (CVE) |
| °ü·Ã URL |
2601 (SecurityFocus) |
| °ü·Ã URL |
6422 (ISS) |
|