| Ãë¾àÁ¡ID |
22034 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç IIS 5.0 À¥¼¹ö¿¡´Â .printer ISAPI È®ÀåÀÌ ¸ÅÇεǾî ÀÖ´Ù. ÇØ´ç IIS (Internet Information Server) 5.0 À¥¼¹ö´Â Internet Printing Protocol (IPP)À» Áö¿øÇϴµ¥ ÀÌ ±â´ÉÀº µðÆúÆ®·Î ¼³Ä¡µÇ¸ç ISAPIÀÇ È®ÀåÀ¸·Î½á IIS5¿¡ ±¸ÇöµÇ¾î ÀÖ´Ù. ¿©±â¿¡´Â Àû¾îµµ Buffer Overflow¿Í °°Àº ÇѰ¡Áö ÀÌ»óÀÇ º¸¾È»óÀÇ ¹®Á¦Á¡ÀÌ °è¼Ó ¹ß°ßµÇ¾î ¿Ô´Ù. µû¶ó¼ ÀÌ·¯ÇÑ ±â´ÉÀ» »ç¿ëµÇ°í ÀÖ´Ù¸é Disable ÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. Windows 2000¿¡ ÀÖ´Â Internet Printing ISAPI extension¿¡¼ÀÇ ÃÖ±Ù¿¡ º¸°íµÈ Buffer Overflow ¹®Á¦Á¡Àº IIS 5.0À» ÅëÇØ °Ç³×Áø ±ä ½ºÆ®¸²ÀÇ ÇÁ¸°Æ® ¿äûÀ» ÅëÇÏ¿© °ø°ÝÀÚ´Â ¿ø°ÝÀ¸·Î °ü¸®ÀÚ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ´Ù. À̰ÍÀº ¸Å¿ì ½É°¢ÇÑ Ãë¾àÁ¡À¸·Î ¸ðµç IIS 5.0 °ü¸®ÀÚµéÀº Áï½Ã Patch¸¦ ¼³Ä¡ÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. Buffer Overflow ¹®Á¦Á¡¿¡ °üÇÑ ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ »çÀÌÆ®¿¡¼ º¼ ¼ö ÀÖ´Ù: http://www.cert.org/advisories/CA-2001-10.html
* Note : ÀÌ Á¡°ËÇ׸ñÀº ¾ÈÀüÇÑ Á¡°ËÀ» À§Çؼ IIS 5.0 .printer ISAPI ÇÊÅͰ¡ Àû¿ëµÇ¾î ÀÖ´ÂÁö ¸¸À» Å×½ºÆ®ÇÑ´Ù. ¸¸¾à ¹öÆÛ ¿À¹öÇ÷ο쿡 ÀÇÇÑ ½ÇÁ¦ Å×½ºÆ®¸¦ ¿øÇÑ´Ù¸é, Á¤Ã¥ÆíÁý±â¿¡¼ "Denial of Service Attacks"¿¡ ÀÖ´Â "www/IIS5/ipp_bof/real" Ç׸ñÀ» Enable ½ÃŲ ÈÄ Á¡°ËÀ» ÇÏ¸é µÈ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/2674 http://www.iss.net/security_center/static/6485.php
* Platforms Affected: Microsoft IIS 5.0 Windows 2000 ¸ðµç ¹öÀü |
| ÇØ°áÃ¥ |
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀÎÅÍ³Ý ¼ºñ½º °ü¸®ÀÚ¿¡¼ ÀÎÅÍ³Ý ÇÁ¸°ÆÃ ISAPI (.printer) È®ÀåÀ» Unmap ÇÏ¿©¾ß ÇÑ´Ù.
ÀÎÅÍ³Ý ÇÁ¸°ÆÃ ISAPI (.printer) È®ÀåÀ» UnmapÇϱâ À§Çؼ´Â: 1. 'ÀÎÅÍ³Ý ¼ºñ½º °ü¸®ÀÚ'¸¦ ¿ÀÇÂÇÑ´Ù. 2. ÇØ´ç À¥¼¹ö¿¡ ¿À¸¥ÂÊ ¸¶¿ì½º ¹öưÀ» Ŭ¸¯ÇÑ´Ù. ÆîÃÄÁø ¸Þ´º¿¡¼ 'µî·ÏÁ¤º¸'¸¦ ¼±ÅÃÇÑ´Ù. 3. '¸¶½ºÅÍ ¼Ó¼º'ÀÇ 'WWW ¼ºñ½º'°¡ ¼±ÅÃµÈ »óÅ¿¡¼ 'ÆíÁý'À» Ŭ¸¯Çϰí 'Ȩ µð·ºÅ͸®' ÅÇ¿¡¼ '±¸¼º'À» Ŭ¸¯ÇÑ´Ù. ¸®½ºÆ®·Î ºÎÅÍ .printer·ÎÀÇ ÂüÁ¶¸¦ Á¦°ÅÇÑ´Ù.
-- ȤÀº --
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS01-023À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms01-023.asp |
| °ü·Ã URL |
CVE-2001-0241 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|