Ãë¾àÁ¡ID |
22458 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç BitDefender Update ¼¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. BitDefender Update Server´Â ·ÎÄà ³×Æ®¿öÅ© »óÀÇ 'Security for Fileservers' ±×¸®°í 'Enterprise Manager (BDEM)'À» Æ÷ÇÔÇÑ BitDefender Á¦Ç°µé¿¡ ´ëÇÑ Áß¾ÓÁýÁßÈµÈ ¾÷µ¥ÀÌÆ®¸¦ À§ÇØ »ç¿ëµÈ´Ù. BitDefender Update Server ¹öÀü 2.5.0.0À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à BitDefender HTTP Server°¡ ¾÷µ¥ÀÌÆ® ¹èÆ÷¿ëÀ¸·Î »ç¿ëµÈ´Ù¸é BitDefender HTTP Server (http.exe)·ÎÀÇ "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/486701/30/0/threaded http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/ http://secunia.com/advisories/28578
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SOFTWIN, BitDefender Update Server ¹öÀü 2.5.0.0À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡Çϰųª ÃֽŹöÀüÀÇ bitdefender·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://www.bitdefender.com/ |
°ü·Ã URL |
CVE-2008-0396 (CVE) |
°ü·Ã URL |
27358 (SecurityFocus) |
°ü·Ã URL |
39802 (ISS) |
|