| Ãë¾àÁ¡ID |
16059 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
ÇØ´ç HPUX ftpd µ¥¸óÀÇ ¹öÀüÀº REST ¸í·ÉÀ» ÅëÇÑ ¸Þ¸ð¸® ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. REST ¸í·ÉÀº »ç¿ëÀÚ°¡ ÀÌÀü À§Ä¡¿¡¼ ¾÷·Îµå³ª ´Ù¿î·Îµå¸¦ Àç°³ÇÏ°Ô ÇØ ÁÖ´Â ¸ñÀûÀ¸·Î ¾²ÀδÙ. HP-UX ¹öÀü 11.00¿¡ žÀçµÈ FTP ¼¹ö ¹öÀü 1.1.214.4¿¡ ÀÖ´Â REST ¸í·ÉÀÇ ±¸Çö¿¡´Â º¸¾È»óÀÇ °áÇÔÀ» °¡Áö°í ÀÖÀ¸¸ç, ÀÌ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÇÁ·Î¼¼½ºÀÇ ¸Þ¸ð¸®¿¡ ÀÖ´Â ¾î¶² ƯÁ¤ À§Ä¡ÀÇ ³»¿ëµéÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸í·É¿¡ Àß °è»êµÈ ¼ýÀÚ Àμö¸¦ ÁÜÀ¸·Î½á, ÇÁ·Î¼¼½ºÀÇ ¸Þ¸ð¸®¿¡ ÀÖ´Â ±× ¼ýÀÚ À§Ä¡ÀÇ ³»¿ëµéÀÌ º¸¿©Áöµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â /etc/passwd¿Í °°Àº Áß¿äÇÑ ÆÄÀϵéÀÇ ³»¿ëµéÀ» º¸´Âµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/323989 http://www.securiteam.com/unixfocus/5VP011PAAE.html http://archives.neohapsis.com/archives/bugtraq/2003-06/0033.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: HP-UX 11.00 FTP ¼¹ö ¹öÀü 1.1.214.4 |
| ÇØ°áÃ¥ |
HP-UX 11.00¿¡ ´ëÇØ¼, http://itrc.hp.com ·ÎºÎÅÍ PHNE_21936 ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
7825 (SecurityFocus) |
| °ü·Ã URL |
12195 (ISS) |
|