English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21171
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ¸î¸î Linux ¹èÆ÷µé¿¡ ÀÖ´Â ht://dig ÇÁ·Î±×·¥Àº htsearch CGI¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ÀÓÀÇÀÇ ÆÄÀÏÀ» °Ë»öÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
ht://dig ÇÁ·Î±×·¥Àº ¹«·á¹èÆ÷ ¹× °ø°³¼Ò½º ±â¹ÝÀÇ À¥°Ë»ö ¿£Áø ¹× Àε¦½Ì ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù.
htsearch CGI¿¡ ÀÖ´Â Ãë¾àÁ¡Àº ´ÙÀ½°ú °°ÀÌ »ç¿ëµÉ ¼ö ÀÖ´Ù:
(1) /dev/zero¿Í °°Àº Ư¼ö ÆÄÀÏÀ» ¸í½ÃÇÔÀ¸·Î½á ¼­ºñ½º°ÅºÎ (CPU °í°¥)À» ÀÏÀ¸Å²´Ù.
(2) ƯÁ¤ ÆÄÀÏÀ» ¸í½ÃÇÑ ¾î¶² ¼³Á¤ÆÄÀÏÀ» ¾÷·Îµå ÇÔÀ¸·Î½á ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐÀ» ¼ö ÀÖ´Ù.

À̰ÍÀº À¥ ÀÎÅÍÆäÀ̽º·ÎºÎÅÍ ¸í·ÉÇà ¶óÀÎ ÀμöµéÀ» »ç¿ë°¡´ÉÇÏ´Ù´Â »ç½Ç¿¡ ±âÀÎÇÑ´Ù. ƯÈ÷, -c [ÆÄÀϸí] Àμö´Â ƯÁ¤ ¼³Á¤ÆÄÀÏÀ» ¸í½ÃÇϴµ¥ »ç¿ëµÈ´Ù.

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
ht://Dig 3.1.0b2 ÀÌ»ó, 3.1.5¿Í 3.2.0b3 ±îÁöÀÇ ¹öÀüµé

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/3410
http://www.iss.net/security_center/static/7263.php
ÇØ°áÃ¥ ´ÙÀ½ HT://Dig À¥»çÀÌÆ®·ÎºÎÅÍ Â÷±â ¸±¸®Áî ¹öÀüÀÎ 3.1.6 À̳ª 3.2.0b4 ȤÀº ½Å±Ô ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
http://www.htdig.org/files/snapshots/

-- ȤÀº --

´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵带 ´Ù¿î·Îµå¹Þ¾Æ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://online.securityfocus.com/bid/3410/solution/
°ü·Ã URL CVE-2001-0834 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)