| Ãë¾àÁ¡ID |
21190 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ OracleÀÇ Web Listener(Oracle Application ServerÀÇ ±¸¼º¿ä¼Ò)°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. À̰ÍÀº Remote Attacker°¡ À¥¼¹ö¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà°¡´ÉÇÏ°Ô ÇØ ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/1053
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
¸¸¾à "ows-bin" µð·ºÅ丮°¡ ¿À¶óŬ Application ¼¹ö °ü¸®ÀÚ¿¡ ÀÇÇØ »ç¿ëµÇ´Â µðÆúÆ® CGI µð·ºÅ丮¶ó¸é ows-bin °¡»ó(virtual) µð·ºÅ丮¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
OSA(Oracle Application Server)°¡ ¼³Ä¡µÈ ÈÄ¿¡ µðÆúÆ® ¼ÂÆÃÀ» ±×´ë·Î ¾´´Ù¸é ¹®Á¦°¡ µÈ´Ù. Oracle Web Listener¿¡ ÀÖ´Â "ows-bin" °¡»ó µð·ºÅ丮´Â ÀϹÝÀûÀÎ À¥¼¹ö»óÀÇ cgi-bin°ú °°Àº ¿ªÇÒÀ» Çϴµ¥ µðÆúÆ®·Î (OracleÀÌ c:\ornant¿¡ ÀνºÅç µÇ¾ú´Ù¸é) C:\orant\ows\4.0\bin¿¡ ³õ¿©Áø´Ù. ÀÌ µð·ºÅ丮´Â »ó´ç¼öÀÇ batch ÆÄÀÏ, DLL, ±×¸®°í ½ÇÇàÆÄÀÏµé »Ó¸¸ ¾Æ´Ï¶ó Listener ÀÚü¸¦ À§ÇÑ Binary À̹ÌÁö ÆÄÀϵµ Æ÷ÇÔÀ» ÇÑ´Ù. ½ÉÁö¾î ÀÌ µðÆúÆ® ¼ÂÆÃÀ» ¹Ù²Ù¾ú´õ¶óµµ »õ·Î¿î "ows-bin" µð·ºÅ丮¿¡ batch ÆÄÀϵéÀÌ ÀÖÀ» °æ¿ì¿¡µµ ÀÌ·¯ÇÑ À§ÇèÀº »óÁ¸ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0169 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|