Ãë¾àÁ¡ID |
23210 |
À§Çèµµ |
30 |
Æ÷Æ® |
8080, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Symantec Backup Exec System RM´Â 'filename' Àμö¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Symantec Backup Exec System Recovery Manager 7.0.4 ÀÌÀüÀÇ 7.x ±×¸®°í 8.0.2 ÀÌÀüÀÇ 8.x ¹öÀüµéÀº '/axis/reportsfile' ½ºÅ©¸³Æ®ÀÇ 'filename' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(\..\)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ HTTP GET ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://securityresponse.symantec.com/avcenter/security/Content/2008.05.28c.html http://secunia.com/advisories/30432
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Symantec, BackupExec System Recovery Manager 7.0 Symantec, BackupExec System Recovery Manager 7.0.1 Symantec, BackupExec System Recovery Manager 7.0.2 Symantec, BackupExec System Recovery Manager 7.0.3 Symantec, BackupExec System Recovery Manager 8.0 Symantec, BackupExec System Recovery Manager 8.0.1 |
ÇØ°áÃ¥ |
´ÙÀ½ SYM08-013À» ÂüÁ¶ÇÏ¿© Backup Exec System Recovery ManagerÀÇ ÃֽŠ¹öÀü(7.0.4 ȤÀº 8.0.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://securityresponse.symantec.com/avcenter/security/Content/2008.05.28c.html |
°ü·Ã URL |
CVE-2008-2512 (CVE) |
°ü·Ã URL |
29350 (SecurityFocus) |
°ü·Ã URL |
42714 (ISS) |
|