English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16127
À§Çèµµ 40
Æ÷Æ® 69
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù TFTP
»ó¼¼¼³¸í ÇØ´ç Kiwi CatTools TFTP ¼­¹ö´Â µð·ºÅ丮 Ž»ö °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Kiwi CatTools´Â ÀåÄ¡ ±¸¼º °ü¸®¸¦ À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Kiwi CatTools¿¡ ÀÖ´Â TFTP ¼­¹ö 2.0.0¿¡¼­ 3.2.8±îÁöÀÇ ¹öÀüµéÀº µð·ºÅ丮 Ž»ö ½ÃÄö½ºµéÀÇ ÆÄÀϸíµéÀ» ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇؼ­, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" µð·ºÅ丮 Ž»ö ½ÃÄö½ºµé(//..//)À» Æ÷ÇÔÇÏ°í ÀÖ´Â Àß Á¶ÀÛµÈ PUT ȤÀº GET ¸í·ÉÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ°í TFTP root µð·ºÅ丮 ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀϵéÀ» ¾÷·Îµå ȤÀº ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/459500/30/0/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052288.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052697.html
http://secunia.com/advisories/24103/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Kiwi Enterprises, Kiwi CatTools 2.0.0¿¡¼­ 3.2.8±îÁöÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ Kiwi Enterprises º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© Kiwi CatToolsÀÇ °¡Àå ÃֽŠ¹öÀü(3.2.9 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.kiwisyslog.com/kb/idx/5/178/article/
°ü·Ã URL CVE-2007-0888 (CVE)
°ü·Ã URL 22490 (SecurityFocus)
°ü·Ã URL 32398 (ISS)