Ãë¾àÁ¡ID |
23190 |
À§Çèµµ |
40 |
Æ÷Æ® |
7205,7211 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Daemon |
»ó¼¼¼³¸í |
Novell Groupwise WebAccessÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼¹ö¿¡´Â HTTP Basic ÀÎÁõ 󸮿¡¼ÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Novell GroupWise (GW) WebAccess 7.0 SP2 ÀÌÀüÀÇ ¹öÀüµéÀº GWINTER.exe¿¡ ÀÇÇÑ HTTP Basic ÀÎÁõ ¿äû¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿©, ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Àß Á¶ÀÛµÈ ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç HTTP ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/archive/1/466212/100/0/threaded http://www.zerodayinitiative.com/advisories/ZDI-07-015.html http://www.securitytracker.com/id?1017932 http://secunia.com/advisories/24944
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Novell GroupWise 7.0 Novell GroupWise 7.0 SP1 Novell NetWare 5.1, 6, 6.5 Microsoft Windows Any version SuSE Linux Enterprise Server Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Novell ´Ù¿î·Îµå À¥ »çÀÌÆ®µé¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Novell Groupwise WebAccess¸¦ À§ÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.novell.com/Download?buildid=8RF83go0nZg~ http://download.novell.com/Download?buildid=O9ucpbS1bK0~ |
°ü·Ã URL |
CVE-2007-2171 (CVE) |
°ü·Ã URL |
23556 (SecurityFocus) |
°ü·Ã URL |
33744 (ISS) |
|