English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22137
À§Çèµµ 40
Æ÷Æ® 8888
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Sun AnswerBook2 dwhttpd´Â Format String Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Sun »çÀÇ AnswerBook2´Â »ç¿ëÀÚµéÀÌ À¥ ºê¶ó¿ìÁ ÀÌ¿ëÇÏ¿© Sun ¿Â¶óÀÎ ¹®¼­¸¦ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â À¯Æ¿¸®Æ¼ÀÌ´Ù. Inso DynaWeb À¥¼­¹öÀÎ dwhttpd´Â Sun »çÀÇ AnswerBook2¿Í °°Àº Á¦Ç°µé¿¡¼­ ºÎºÐÀûÀÎ ±¸¼º¿ä¼Ò·Î½á »ç¿ëµÈ´Ù. AnswerBook2´Â Solaris ¿î¿µÃ¼Á¦¿¡ ¼³Ä¡µÇ¾î °ø±ÞµÇ°í ÀÖ´Ù.
AnswerBook2 1.2¿¡¼­ 1.4.3 ¹öÀüµéÀº dwhttpd µ¥¸ó¿¡ ÀÖ´Â Format String Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Àß Á¶ÀÛµÈ GET ¿äûÀ¸·Î ÆÄÀÏ¸í ´ë½Å, 16ÁøÀ¸·Î ÀÎÄÚµùµÈ ¹®ÀÚµéÀÇ ±ä ÀԷ¹®ÀÚ¿­À» º¸³¿À¸·Î½á À¥¼­¹öÀÇ ±ÇÇÑÀÎ "daemon"ÀÇ ±ÇÇÑÀ¸·Î ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Ãë¾àÇÑ Ç÷§Æû:
DynaWeb dwhttpd 4.0.2a7a
DynaWeb dwhttpd 4.1a6
Sun AnswerBook2 1.2
Sun AnswerBook2 1.3
Sun AnswerBook2 1.4
Sun AnswerBook2 1.4.1
Sun AnswerBook2 1.4.2
Sun AnswerBook2 1.4.3

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/unixfocus/5SP081F80K.html
http://online.securityfocus.com/bid/5384
http://www.iss.net/security_center/static/9758.php
ÇØ°áÃ¥ Vender¿Í »óÀÇÇÏ¿© AnswerBook2 ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:

AnswerBook 1.4.2: 110531-01 ÆÐÄ¡ Àû¿ë.
AnswerBook 1.4.2_x86: 110537-01 ÆÐÄ¡ Àû¿ë.
AnswerBook 1.4.3: 110532-01 ÆÐÄ¡ Àû¿ë.
AnswerBook 1.4.3_x86: 110538-01 ÆÐÄ¡ Àû¿ë.

* ¾Ë¸²: AnswerBook2 À¥¼­¹ö´Â ´ÜÁ¾µÇ¾î Solaris ¸±¸®Áîµé (Solaris 9)¿¡ ´õ ÀÌ»ó Æ÷ÇÔµÇÁö ¾Ê´Â´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)