English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22458
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç BitDefender Update ¼­¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. BitDefender Update Server´Â ·ÎÄà ³×Æ®¿öÅ© »óÀÇ 'Security for Fileservers' ±×¸®°í 'Enterprise Manager (BDEM)'À» Æ÷ÇÔÇÑ BitDefender Á¦Ç°µé¿¡ ´ëÇÑ Áß¾ÓÁýÁßÈ­µÈ ¾÷µ¥ÀÌÆ®¸¦ À§ÇØ »ç¿ëµÈ´Ù. BitDefender Update Server ¹öÀü 2.5.0.0À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à BitDefender HTTP Server°¡ ¾÷µ¥ÀÌÆ® ¹èÆ÷¿ëÀ¸·Î »ç¿ëµÈ´Ù¸é BitDefender HTTP Server (http.exe)·ÎÀÇ "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/486701/30/0/threaded
http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/
http://secunia.com/advisories/28578

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SOFTWIN, BitDefender Update Server ¹öÀü 2.5.0.0À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡Çϰųª ÃֽŹöÀüÀÇ bitdefender·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.bitdefender.com/
°ü·Ã URL CVE-2008-0396 (CVE)
°ü·Ã URL 27358 (SecurityFocus)
°ü·Ã URL 39802 (ISS)