English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16075
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç WU-FTPD ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö¿¡´Â realpath() ÇÔ¼ö¿¡ ÀÖ´Â off-by-one ¿¡·¯¿¡ ÀÇÇÑ ¹öÆÛ ¿À¹öÇ÷ο찡 Á¸ÀçÇÑ´Ù.
realpath() ÇÔ¼ö´Â '/', './', '../' ȤÀº ½Éº¼¸¯ ¸µÅ©(symbolic link)µé°ú °°Àº °ªµéÀ» Æ÷ÇÔÇÒ ¼ö ÀÖ´Â °æ·Î¿¡ ±â¹ÝÀ» µÐ ÆÄÀÏÀÇ Ç¥ÁØÀÇ Àý´ë °æ·Î¸íÀ» ÇØ¼®ÇØ ÁÖ´Â C ¶óÀ̺귯¸® ÇÁ·Î½Ãµà¾îÀÌ´Ù. WU-FTPD 2.5.0¿¡¼­ 2.6.2 »çÀÌÀÇ ¹öÀüµéÀº realpath()ÀÇ ±¸Çö¿¡ off-by-one ½ºÅà ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸°íµÇ¾ú´Ù. ¿µÇâÀ» ¹Þ´Â ¼­¹ö¿¡ °æ·Î¸íÀÇ ±æÀÌ MAXPATHLEN+1À» Àμö·Î ÇÏ´Â STOR, RETR, APPE, DELE, MKD, RMD, STOU, ȤÀº RNTOÀ» Æ÷ÇÔÇÑ ´Ù¾çÇÑ FTP ¸í·ÉµéÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ´Â ¼­ºñ½º °ÅºÎ¸¦ À¯¹ßÇϰųª root ±ÇÇÑÀ¸·Î °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WU-FTP ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/743092
http://marc.theaimsgroup.com/?l=bugtraq&m=105967301604815&w=2
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html
http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt
http://marc.theaimsgroup.com/?l=bugtraq&m=106002488209129&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=106001702232325&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Washington University, wu-ftpd 2.5.0¿¡¼­ 2.6.2 »çÀÌÀÇ ¹öÀüµé
Unix Any version
Linux Any version
ÇØ°áÃ¥ FreeBSDÀÇ °æ¿ì:
´ÙÀ½ FreeBSD Security Advisory FreeBSD-03:08.realpath¸¦ ÂüÁ¶ÇÏ¿© FreeBSDÀÇ °¡Àå ÃֽйöÀü(4.8-STABLE ȤÀº 2003-08-03 ÀÌÈÄ¿¡ Ãâ½ÃµÈ ÃÖ½ÅÀÇ Security Branch)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:08.realpath.asc

OpenBSD 3.3 ÀÌÇÏÀÇ °æ¿ì:
´ÙÀ½ OpenBSD 015: SECURITY FIX: 2003³â 8¿ù 4ÀÏÀÚ¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.openbsd.org/errata32.html#realpath

NetBSD 1.5, 1.5.1, 1.5.2, 1.5.3, 1.6 ±×¸®°í 1.6.1ÀÇ °æ¿ì:
´ÙÀ½ NetBSD Security Advisory 2003-011À» ÂüÁ¶ÇÏ¿© NetBSDÀÇ °¡Àå ÃֽйöÀü(NetBSD-current ȤÀº 2003³â 8¿ù 5ÀÏ È¤Àº ÀÌÈÄ Ãâ½ÃµÈ ÃÖ½ÅÀÇ NetBSD 1.6 branch)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://archives.neohapsis.com/archives/netbsd/2003-q3/0019.html

HP-UX 11.00, 11.11, ±×¸®°í 11.22ÀÇ °æ¿ì:
´ÙÀ½ Hewlett-Packard Company Security Bulletin HPSBUX0309-277À» ÂüÁ¶ÇÏ¿© ±Ç°íÇÑ ÀýÂ÷¸¦ µû¸¥´Ù:
http://www.securityfocus.com/advisories/5765

±× ¿ÜÀÇ ½Ã½ºÅÛ:
WU-FTPD´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2003-0466 (CVE)
°ü·Ã URL 8315 (SecurityFocus)
°ü·Ã URL 12785 (ISS)