| Ãë¾àÁ¡ID |
16056 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
Debian 2.2 (potato) ¿¡ žÀçµÇ¾î ÀÖ´Â ProFTPd ÇÁ·Î±×·¥¿¡´Â ´ÙÀ½°ú °°Àº 2°¡Áö ¹®Á¦Á¡ÀÌ Á¸ÀçÇÑ´Ù.
1. ù¹øÂ° ¹®Á¦Á¡Àº »ç¿ëÀÚÀÇ Àǵµ¿Í ¹«°üÇÏ°Ô proftpd µ¥¸óÀÌ root ±ÇÇÑÀ¸·Î µ¿ÀÛÇÏ´Â ¼³Á¤»óÀÇ ¿À·ùÀÌ´Ù. ÀÌ´Â ¼³Ä¡ ½Ã, À͸í(anonymous)ÀÇ Á¢¼ÓÀ» Çã¿ëÇϱâ À§ÇØ »ç¿ëÀÚ°¡ "yes" ¸¦ ¼±ÅÃÇÒ °æ¿ì, /etc/proftpd.conf ÆÄÀÏ¿¡´Â 'run as uid/gid root' ¼³Á¤ ¿É¼ÇÀÌ ±×´ë·Î ³²°ÜÁø ä 'run as uid/gid nobody' ¼³Á¤ ¿É¼ÇÀÌ Ãß°¡µÇ±â ¶§¹®¿¡ »ý°Ü³´Ù.
2. /varÀÌ ½Éº¼¸¯ ¸µÅ©ÀÎ »óÅ¿¡¼ proftpd°¡ Àç½ÃÀÛµÉ ¶§ ¹ö±×°¡ Á¸ÀçÇÑ´Ù. Proftpd°¡ ÁßÁöÇÒ ¶§ /var ½Éº¼¸¯ ¸µÅ©´Â Á¦°ÅµÈ´Ù. ±×¸®°í ´Ù½Ã ½ÃÀÛµÉ ¶§ /var ¶ó´Â À̸§ÀÇ ÆÄÀÏÀÌ »ý¼ºµÈ´Ù.
* Âü°í »çÀÌÆ®: http://www.debian.org/security/2001/dsa-032
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Debian 2.2 (potato) ProFTPd ¹öÀü 1.2.0pre10-2.0potato1 ÀÌÀü ÆÐŰÁö |
| ÇØ°áÃ¥ |
ÇöÀç Debian À¥ »çÀÌÆ®¿¡¼´Â ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ ´õ ÀÌ»ó Áö¿øÇÏÁö ¾Ê°í ÀÖ´Ù. º¥´õ¿¡ ¹®ÀÇÇÏ¿© proftpdÀÇ °¡Àå ÃֽйöÀü (proftpd-1.2.0pre10-2potato1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0456 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
6208 (ISS) |
|