English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16059
À§Çèµµ 30
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç HPUX ftpd µ¥¸óÀÇ ¹öÀüÀº REST ¸í·ÉÀ» ÅëÇÑ ¸Þ¸ð¸® ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. REST ¸í·ÉÀº »ç¿ëÀÚ°¡ ÀÌÀü À§Ä¡¿¡¼­ ¾÷·Îµå³ª ´Ù¿î·Îµå¸¦ Àç°³ÇÏ°Ô ÇØ ÁÖ´Â ¸ñÀûÀ¸·Î ¾²ÀδÙ. HP-UX ¹öÀü 11.00¿¡ žÀçµÈ FTP ¼­¹ö ¹öÀü 1.1.214.4¿¡ ÀÖ´Â REST ¸í·ÉÀÇ ±¸Çö¿¡´Â º¸¾È»óÀÇ °áÇÔÀ» °¡Áö°í ÀÖÀ¸¸ç, ÀÌ´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÇÁ·Î¼¼½ºÀÇ ¸Þ¸ð¸®¿¡ ÀÖ´Â ¾î¶² ƯÁ¤ À§Ä¡ÀÇ ³»¿ëµéÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸í·É¿¡ Àß °è»êµÈ ¼ýÀÚ Àμö¸¦ ÁÜÀ¸·Î½á, ÇÁ·Î¼¼½ºÀÇ ¸Þ¸ð¸®¿¡ ÀÖ´Â ±× ¼ýÀÚ À§Ä¡ÀÇ ³»¿ëµéÀÌ º¸¿©Áöµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â /etc/passwd¿Í °°Àº Áß¿äÇÑ ÆÄÀϵéÀÇ ³»¿ëµéÀ» º¸´Âµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼­¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/323989
http://www.securiteam.com/unixfocus/5VP011PAAE.html
http://archives.neohapsis.com/archives/bugtraq/2003-06/0033.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
HP-UX 11.00
FTP ¼­¹ö ¹öÀü 1.1.214.4
ÇØ°áÃ¥ HP-UX 11.00¿¡ ´ëÇØ¼­, http://itrc.hp.com ·ÎºÎÅÍ PHNE_21936 ÆÐÄ¡¸¦ ±¸ÇÏ¿© Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 7825 (SecurityFocus)
°ü·Ã URL 12195 (ISS)