English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16023
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç FTP ¼­¹ö´Â glob() ÇÔ¼ö³»ÀÇ ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù.
glob()´Â ÆÄÀÏ¸í ÆÐÅÏ ¸ÅĪÀ» ±¸ÇöÇÑ ÇÔ¼ö·Î À¯´Ð½º Shell¿¡ ÀÇÇØ »ç¿ëµÇ´Â ÆÐÅÏ ¸Åεé°ú À¯»çÇÑ ±ÔÄ¢µéÀ» °¡Áö°í ÀÖ´Ù. °æ·Î¸í »ý¼º±â¶ó ºÒ¸®´Â ÀÌ ÇÔ¼ö´Â ÇÑ ¼ÂÀÇ ÆÄÀϸíµéÀ» Ç¥ÇöÇÏ´Â ÀÔ·Â ÆÐÅÏÀ» ¹Þ¾Æµé¿©¼­ ±× ÆÐÅϰú ÀÏÄ¡ÇÏ´Â ¾×¼¼½º °¡´ÉÇÑ °æ·Î¸íµéÀÇ ¸®½ºÆ®¸¦ ¹Ýȯ(return) ÇØ ÁØ´Ù. ÀÔ·Â ÆÐÅÏÀº Ư¼öÇÑ Meta ¹®ÀÚµé Áï, *?[]{}~ À» »ç¿ëÇÏ¿© Ç¥ÇöÇÑ´Ù. ¿¹¸¦µé¾î, ÆÐÅÏ '/e*' ´Â ¹®ÀÚ 'e'·Î ½ÃÀ۵Ǵ ÆÄÀϽýºÅÛÀÇ root¿¡ ÀÖ´Â ¸ðµç µð·ºÅ丮¿Í ÆÄÀϵéÀ» Ç¥ÇöÇÏ´Â °ÍÀÌ µÈ´Ù.
BSD ftp µ¥¸ó°ú ÆÄ»ýµÈ µ¥¸óµé (IRIX ftpd ȤÀº Kerberos 5¿¡ žÀçµÈ ftp µ¥¸ó)Àº ¾ÇÀÇÀûÀÎ »ç¿ëÀڵ鿡 ÀÇÇØ root ±ÇÇÑÀÌ È¹µæµÉ ¼ö ÀÖ´Â ¿©·¯ °¡Áö ¹öÆÛ ¿À¹öÇ÷οìµéÀ» °¡Áö°í ÀÖ´Ù. °æ·Î¸í ¹®ÀÚ¿­¿¡ ¹°°áÇ¥½Ã (~)¿Í ¿©·¯ °¡Áö wildcard ¹®ÀÚµéÀ» Æ÷ÇÔÇÏ´Â ¿äûÀ» FTP ¼­¹ö·Î º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç root ±ÇÇÑÀ» ȹµæÇϱâ À§ÇÏ¿© FTP ¼­¹ö»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇÒ ¼ö ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§Çؼ­´Â °ø°ÝÀÚ´Â ftp °èÁ¤ÀÌ ÀÖ¾î¾ß Çϸç, µð·ºÅ丮°¡ »ý¼º °¡´ÉÇϰųª ¾Æ´Ï¸é ÃæºÐÇÑ ±æÀ̸¦ °¡Áø µð·ºÅ丮¸íÀÌ ¹Ì¸® Á¸ÀçÇϰí ÀÖ¾î¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2001-07.html
http://www.iss.net/security_center/static/6332.php

Ãë¾àÇÑ Ç÷§Æû:
Caldera UnixWare 7
IRIX 6.5.x
MIT Kerberos 5: All Versions
NetBSD: All Versions
OpenBSD 2.8 or earlier
FreeBSD 4.2 or earlier CVE-2001-0247
HP-UX 11.00 CVE-2001-0248
Solaris 8 CVE-2001-0249
ÇØ°áÃ¥ For FreeBSD 4.2:
´ÙÀ½ CERT ±Ç°í¾È CA-2001-07À» ÂüÁ¶ÇÏ¿© FreeBSDÀÇ ÃֽйöÀü (FreeBSD 4.2-STABLE, FreeBSD 5.0-CURRENT, ȤÀº ÀÌÈÄ) À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cert.org/advisories/CA-2001-07.html

For Sun Solaris
Vender¿Í »óÀÇÇÏ¿© °¢ ½Ã½ºÅÛ¿¡ ¸Â´Â ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
Sun Solaris 2.5 : 103577-1
Sun Solaris 2.5.1 : 103603-16
Sun Solaris 2.6 : 106301-03
Sun Solaris 7.0 : 110646-02
Sun Solaris 8_sparc : 111606-01


For Fujitsu UXP/V:
´ÙÀ½ CERT ±Ç°í¾È CA-2001-07À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.cert.org/advisories/CA-2001-07.html

For NetBSD All versions:
´ÙÀ½ NetBSD º¸¾È ±Ç°í¾È 2001-005¸¦ ÂüÁ¶ÇÏ¿© NetBSDÀÇ ÃֽйöÀü (NetBSD-Current dated 4-03-2001, ȤÀº ÀÌÈÄ) À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://online.securityfocus.com/advisories/3207

´Ù¸¥ ¹èÆ÷ÆÇµé:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.


±âŸ ÂüÁ¶ÇÒ »çÀÌÆ®µé:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0247
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0248
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0249

http://online.securityfocus.com/bid/2548
http://online.securityfocus.com/bid/2550
http://online.securityfocus.com/bid/2552
°ü·Ã URL CVE-2001-0247,CVE-2001-0248,CVE-2001-0249 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)