Ãë¾àÁ¡ID |
23184 |
À§Çèµµ |
40 |
Æ÷Æ® |
8080,443 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Daemon |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â 5.1.0.2 ÀÌÀüÀÇ IBM TPM for OS DeploymentÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Tivoli Provisioning Manager for OS Deployment Fix Pack 1 (¹öÀü 5.1.0.0)°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº HTTP POST ¿äûµé¿¡¼ multipart/form-data¸¦ ó¸®ÇÒ ¶§ÀÇ °ü¸® ¼ºñ½º ³»ÀÇ ¿À·ùµé·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. 8080 ȤÀº 443 Æ÷Æ® »ó¿¡ ÀÛµ¿ ÁßÀÎ °ü¸® ÀÎÅÍÆäÀ̽º·Î Àß Á¶ÀÛµÈ HTTP POST ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ¼¹ö¸¦ Å©·¡½¬ ½ÃÅ°°Å³ª ȤÀº SYSTEM ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ IBM TPM ¼ºñ½ºÀÇ ¹öÀü Á¤º¸¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=49 http://secunia.com/advisories/24717
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ IBM Support & downloads À¥ »çÀÌÆ®¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â IBM TPM (Tivoli Provisioning Manager) for OS DeploymentÀ» À§ÇÑ °¡Àå ÃÖ½ÅÀÇ Fix Pack(5.1.0.2 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www-01.ibm.com/software/tivoli/products/prov-mgr-os-deploy/ |
°ü·Ã URL |
CVE-2007-1868 (CVE) |
°ü·Ã URL |
23264 (SecurityFocus) |
°ü·Ã URL |
33384 (ISS) |
|