English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22087
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í FrontPage Server Extension Sub-Component´Â ¿ø°ÝÁö¿¡¼­ÀÇ Buffer °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
±× Ãë¾àÁ¡Àº Visual InterDev RAD Remote Deployment Support sub-component¶ó ºÒ¸®´Â FrontPage Server ExtensionsÀÇ subcomponent¿¡¼­ ¹öÆÛ üŷÀ» ÇÏÁö ¾Ê¾Æ ¹ß»ýÇÑ´Ù. 'fp30reg.dll'¸¦ °æÀ¯ÇÑ Á¶ÀÛµÈ Request´Â ¿ÜºÎ »ç¿ëÀÚ°¡ IIS 5.0°¡ °¡µ¿µÇ°í Àִ ȣ½ºÆ® »ó¿¡¼­ IWAM_machinenameÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. IIS 4.0ÀÌ °¡µ¿µÇ´Â È£½ºÆ® »ó¿¡¼­´Â SYSTEM ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼öµµ ÀÖ´Ù.
FrontPage Server Extensions´Â IIS 4.0°ú 5.0ÀÇ ºÎ¼ÓÀ¸·Î µþ·Á ³ª¿À¸ç Web sites ±×¸®°í À¥±â¹Ý ÀÀ¿ëµéÀÇ °³¹ßÀ» ¿ëÀÌÇÏ°Ô ÇØ ÁØ´Ù. FrontPage Server Extensions´Â Visual Studio RAD (Remote Application Deployment) Support¶ó ºÒ¸®´Â Ãß°¡ÀûÀÌ°í ¼±Åà »çÇ×ÀÎ sub-component¸¦ Æ÷ÇÔÇÑ´Ù. ÀÌ sub-component´Â Visual InterDev 6.0 »ç¿ëÀÚ°¡ IIS 4.0 ȤÀº 5.0 ¼­¹ö»ó¿¡ COM ¿ÀºêÁ§Æ®µéÀ» µî·ÏÇϰųª Á¦°ÅÇϵµ·Ï ÇØ ÁØ´Ù. Attacker´Â ÀÌ sub-component°¡ ¼³Ä¡µÇ¾î ÀÖ´Â ¾î¶² ¼­¹ö¿¡ ´ëÇØ ¼­¹ö¿ÍÀÇ À¥ ¼¼¼ÇÀ» ¸Î°í ±× ¼­¹ö component·Î ¾ÇÀÇÀûÀÎ ÆÐŶÀ» °Ç³¿À¸·Î½á ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀ» ÇÒ ¼ö ÀÖ´Ù. Attacker´Â ±× ÆÐŶÀ» »ç¿ëÇÏ¿© ¼­¹ö»ó¿¡ ½ÇÇà °¡´ÉÇÑ Äڵ带 ·Îµå½Ã۴µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¸é ±× Äڵ带 IUSR_machinename ±ÇÇÑÀ¸·Î ¼öÇà½Ãų ¼ö ÀÖÀ¸¸ç ¾î¶² Á¶°ÇÇÏ¿¡¼­´Â SYSTEM ±ÇÇÑÀ¸·Î Äڵ带 ¼öÇà½Ãų ¼ö ÀÖ´Ù.
À̰ÍÀº Microsoft ±Ç°í¾È MS01-035¿¡ ÀÚ¼¼ÇÏ°Ô ¼³¸íµÇ¾î ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2906
ÇØ°áÃ¥ Microsoft Security Bulletin MS01-035 (https://technet.microsoft.com/library/security/ms01-035) ¿¡ ¼³¸íµÈ ´ë·Î ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ patch(Q300477)¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.

ÀÌ ÆÐÄ¡¿¡ ´ëÇÑ ´Ù¿î·Îµå À§Ä¡´Â ´ÙÀ½°ú °°´Ù.
* Microsoft Windows NT 4.0:
FrontPage Server Extensions Service Release 1.3 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
* Microsoft Windows 2000:
Windows 2000 Service Pack 3 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
°ü·Ã URL CVE-2001-0341 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)