English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23207
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í ÇØ´ç HP OpenView NNMÀº ÀÓÀÇÀÇ ¸í·É ¼öÇàÀ» Çã¿ëÇÏ´Â ´ÙÁßÀÇ CGI ½ºÅ©¸³Æ®µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. HP OpenView Network Node Manager (NNM)´Â ³×Æ®¿öÅ© »óÀÇ ÀåºñµéÀ» ¹ß°ßÇÏ°í ½ÇÁ¦·Î ¾î¶»°Ô ³×Æ®¿öÅ©°¡ Çü¼ºµÇ¾î ÀÖ´Â Áö¸¦ ¾È³»ÇØ ÁÖ´Â Áöµµ¸¦ Á¦°øÇØ ÁØ´Ù. HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, ±×¸®°í 7.51 ¹öÀüµéÀº "ovlogin.exe", "OpenView5.exe", "snmpviewer.exe", ±×¸®°í "webappmon.exe" CGI ¾îÇø®ÄÉÀ̼ǵ鿡 ÀÖ´Â ´ÙÁßÀÇ ½ºÅà ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Ãë¾àÇÑ CGI ¾îÇø®ÄÉÀ̼ǵé ÁßÀÇ Çϳª·Î ¾ÆÁÖ ±ä Àμö¸¦ º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖÀ¸¸ç À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç HP NNM À¥ ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01188923
http://support.openview.hp.com/patches/patch_index.jsp
http://www.securityfocus.com/archive/1/archive/1/484704/100/0/threaded
http://www.zerodayinitiative.com/advisories/ZDI-07-071.html
http://secunia.com/advisories/27964
http://www.securitytracker.com/id?1019055

* ¿µÇâÀ» ¹Þ´Â È£½ºÆ®:
HP OpenView Network Node Manager 6.41
HP OpenView Network Node Manager 7.01
HP OpenView Network Node Manager 7.51
HP HP-UX B.11.00, B.11.11, ±×¸®°í B.11.23
Microsoft Windows Any version
Linux Any version
Sun Solaris Any version
ÇØ°áÃ¥ ´ÙÀ½ HPSBMA02281 SSRT061261 rev.1À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01188923&jumpid=reg_R1002_USEN
°ü·Ã URL CVE-2007-6204 (CVE)
°ü·Ã URL 26741 (SecurityFocus)
°ü·Ã URL 38892 (ISS)