English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23209
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í ÇØ´ç HP OpenView NNMÀº ÀÓÀÇÀÇ ¸í·É ¼öÇàÀ» Çã¿ëÇÏ´Â ´ÙÁßÀÇ CGI ½ºÅ©¸³Æ®µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. HP OpenView Network Node Manager (NNM)´Â ³×Æ®¿öÅ© »óÀÇ ÀåºñµéÀ» ¹ß°ßÇÏ°í ½ÇÁ¦·Î ¾î¶»°Ô ³×Æ®¿öÅ©°¡ Çü¼ºµÇ¾î ÀÖ´Â Áö¸¦ ¾È³»ÇØ ÁÖ´Â Áöµµ¸¦ Á¦°øÇØ ÁØ´Ù. HP OpenView Network Node Manager (OV NNM) 7.51, ±×¸®°í 7.53 ¹öÀüµéÀº 'OpenView5.exe' CGI ½ºÅ©¸³Æ®ÀÇ 'Action' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Action Àμö¿¡ "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â OpenView5.exe CGI ¾îÇø®ÄÉÀ̼ÇÀ¸·ÎÀÇ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://aluigi.altervista.org/adv/closedviewx-adv.txt
http://www.securityfocus.com/archive/1/490771/30/0/threaded
http://secunia.com/secunia_research/2008-4/advisory/
http://www.securityfocus.com/archive/1/490834/30/0/threaded
http://securitytracker.com/alerts/2008/Apr/1019838.html
http://secunia.com/advisories/29796

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
HP OpenView Network Node Manager 7.51, 7.53
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ À¥»çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡(NNM_01168 ¶Ç´Â NNM_01159)¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01496048
°ü·Ã URL CVE-2008-0068 (CVE)
°ü·Ã URL 28745 (SecurityFocus)
°ü·Ã URL 41790 (ISS)