English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23210
À§Çèµµ 30
Æ÷Æ® 8080, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Symantec Backup Exec System RM´Â 'filename' Àμö¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Symantec Backup Exec System Recovery Manager 7.0.4 ÀÌÀüÀÇ 7.x ±×¸®°í 8.0.2 ÀÌÀüÀÇ 8.x ¹öÀüµéÀº '/axis/reportsfile' ½ºÅ©¸³Æ®ÀÇ 'filename' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(\..\)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ HTTP GET ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securityresponse.symantec.com/avcenter/security/Content/2008.05.28c.html
http://secunia.com/advisories/30432

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Symantec, BackupExec System Recovery Manager 7.0
Symantec, BackupExec System Recovery Manager 7.0.1
Symantec, BackupExec System Recovery Manager 7.0.2
Symantec, BackupExec System Recovery Manager 7.0.3
Symantec, BackupExec System Recovery Manager 8.0
Symantec, BackupExec System Recovery Manager 8.0.1
ÇØ°áÃ¥ ´ÙÀ½ SYM08-013À» ÂüÁ¶ÇÏ¿© Backup Exec System Recovery ManagerÀÇ ÃֽŠ¹öÀü(7.0.4 ȤÀº 8.0.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://securityresponse.symantec.com/avcenter/security/Content/2008.05.28c.html
°ü·Ã URL CVE-2008-2512 (CVE)
°ü·Ã URL 29350 (SecurityFocus)
°ü·Ã URL 42714 (ISS)