English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21190
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ OracleÀÇ Web Listener(Oracle Application ServerÀÇ ±¸¼º¿ä¼Ò)°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. À̰ÍÀº Remote Attacker°¡ À¥¼­¹ö¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà°¡´ÉÇÏ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/1053

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ ¸¸¾à "ows-bin" µð·ºÅ丮°¡ ¿À¶óŬ Application ¼­¹ö °ü¸®ÀÚ¿¡ ÀÇÇØ »ç¿ëµÇ´Â µðÆúÆ® CGI µð·ºÅ丮¶ó¸é ows-bin °¡»ó(virtual) µð·ºÅ丮¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.

OSA(Oracle Application Server)°¡ ¼³Ä¡µÈ ÈÄ¿¡ µðÆúÆ® ¼ÂÆÃÀ» ±×´ë·Î ¾´´Ù¸é ¹®Á¦°¡ µÈ´Ù. Oracle Web Listener¿¡ ÀÖ´Â "ows-bin" °¡»ó µð·ºÅ丮´Â ÀϹÝÀûÀÎ À¥¼­¹ö»óÀÇ cgi-bin°ú °°Àº ¿ªÇÒÀ» Çϴµ¥ µðÆúÆ®·Î (OracleÀÌ c:\ornant¿¡ ÀνºÅç µÇ¾ú´Ù¸é) C:\orant\ows\4.0\bin¿¡ ³õ¿©Áø´Ù.
ÀÌ µð·ºÅ丮´Â »ó´ç¼öÀÇ batch ÆÄÀÏ, DLL, ±×¸®°í ½ÇÇàÆÄÀÏµé »Ó¸¸ ¾Æ´Ï¶ó Listener ÀÚü¸¦ À§ÇÑ Binary À̹ÌÁö ÆÄÀϵµ Æ÷ÇÔÀ» ÇÑ´Ù. ½ÉÁö¾î ÀÌ µðÆúÆ® ¼ÂÆÃÀ» ¹Ù²Ù¾ú´õ¶óµµ »õ·Î¿î "ows-bin" µð·ºÅ丮¿¡ batch ÆÄÀϵéÀÌ ÀÖÀ» °æ¿ì¿¡µµ ÀÌ·¯ÇÑ À§ÇèÀº »óÁ¸ÇÑ´Ù.
°ü·Ã URL CVE-2000-0169 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)