English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16113
À§Çèµµ 40
Æ÷Æ® 69
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù TFTP
»ó¼¼¼³¸í ÇØ´ç HP Ignite-UX´Â TFTP ¼­ºñ½º¸¦ ÅëÇÑ Æнº¿öµå ÆÄÀÏ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Hewlett-Packard Ignite-UX´Â ¿ÏÀüÇÑ HP-UX ½Ã½ºÅÛµéÀ» ¼³Ä¡ÇÏ°í º¹±¸ÇÒ ¼ö ÀÖ´Â µð½ºÅ© À̹ÌÁöµéÀ» »ý¼ºÇϱâ À§ÇÑ HP-UX °ü¸® Åø¼¼Æ®ÀÌ´Ù. C.6.2.241 ¹Ì¸¸ÀÇ HP Ignite-UX ¾îÇø®ÄÉÀ̼ÇÀ» ¿î¿µ ÁßÀÎ HP-UX B.11.00, B11.11, B11.22, ±×¸®°í B.11.23Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ º¸¾ÈÀ» ¿ìȸÇÏ¿© passwd ÆÄÀÏÀÇ º¹»çº»À» °¡Á®°¥ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. HP Ignite-UX´Â À͸íÀ¸·Î ±¸¼º µ¥ÀÌÅ͸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖµµ·Ï TFTP ¼­¹ö¸¦ ÀÌ¿ëÇÑ´Ù. "make_recovery" ¸í·ÉÀ» ´Ù·ç´Â µ¥¿¡ ÀÖ´Â ¿À·ù´Â "/etc/passwd" ÆÄÀÏÀÇ º¹»çº»ÀÌ TFTP ¼­¹ö µð·ºÅ丮 Æ®¸®¿¡ »ý¼ºµÇµµ·Ï ÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À͸íÀÇ ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/16456/
http://www.securitytracker.com/alerts/2005/Aug/1014711.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
HP Ignite-UX C.6.2.240 ÀÌÇÏÀÇ ¹öÀüµé
Hewlett-Packard Company, HP-UX B.11.00
Hewlett-Packard Company, HP-UX B.11.11
Hewlett-Packard Company, HP-UX B.11.22
Hewlett-Packard Company, HP-UX B.11.23
ÇØ°áÃ¥ HP Ignite-UX ¹öÀü C.6.2.241 ÆÐÄ¡µéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. Hewlett-Packard °í°´µéÀº Hewlett-Packard »ç À¥ »çÀÌÆ®ÀÎ http://www.hp.com/go/softwaredepot ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â, B.11.0, B.11.11, B.11.22, ±×¸®°í B.11.23 (Ignite-UX_All_C.6.2.241.depot ÆÐÄ¡´Â ³× °³ ¸ðµÎ¿¡ ´ëÇÑ FixµéÀ» Æ÷ÇÔÇÏ°í ÀÖÀ½) ¹öÀüµé¿¡ ´ëÇÑ ÆÐÄ¡µéÀ» ±¸ÇÒ ¼ö ÀÖ´Ù.

-- ȤÀº --

ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ¿µÇâÀ» ¹Þ´Â TFTP ¼­¹ö¸¦ »ç¿ë ÁßÁöÇÏ¿©¾ß ÇÑ´Ù. ±×·¸Áö ¾ÊÀ¸¸é ½Å·Ú¼ºÀִ ȣ½ºÆ®µé¿¡¼­ ¸¸À¸·Î Á¢±ÙÀ» Á¦ÇÑÇÑ´Ù.
°ü·Ã URL CVE-2004-0951 (CVE)
°ü·Ã URL 14568 (SecurityFocus)
°ü·Ã URL 21858 (ISS)