ProFTPd์˜ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์  CVE-2019-12815

ProFTPd(์ธ๊ธฐ FTP ์„œ๋ฒ„)์—์„œ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ (CVE-2019-12815)์ด ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ž‘์—…์„ ํ†ตํ•ด ์ต๋ช… ์•ก์„ธ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•œ ์„œ๋ฒ„๋ฅผ ํฌํ•จํ•˜์—ฌ "site cpfr" ๋ฐ "site cpto" ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆ ์—†์ด ์„œ๋ฒ„ ๋‚ด์—์„œ ํŒŒ์ผ์„ ๋ณต์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์ทจ์•ฝ์ ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ ์‚ฌ์šฉ๋˜๋ฉฐ ๋Œ€๋ถ€๋ถ„์˜ ๋ฐฐํฌํŒ์— ๋Œ€ํ•ด proftpd ํŒจํ‚ค์ง€์—์„œ ํ™œ์„ฑํ™”๋˜๋Š” mod_copy ๋ชจ๋“ˆ์—์„œ ๋ฐ์ดํ„ฐ ์ฝ๊ธฐ ๋ฐ ์“ฐ๊ธฐ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ์ œํ•œ(์ฝ๊ธฐ ์ œํ•œ ๋ฐ ์“ฐ๊ธฐ ์ œํ•œ)์„ ์ž˜๋ชป ๊ฒ€์‚ฌํ•˜์—ฌ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

Fedora๋ฅผ ์ œ์™ธํ•œ ๋ชจ๋“  ๋ฐฐํฌํŒ์˜ ๋ชจ๋“  ์ตœ์‹  ๋ฒ„์ „์ด ์˜ํ–ฅ์„ ๋ฐ›์Šต๋‹ˆ๋‹ค. ์ˆ˜์ • ์‚ฌํ•ญ์€ ํ˜„์žฌ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค. ๋ฐ˜์ . ์ž„์‹œ ํ•ด๊ฒฐ์ฑ…์œผ๋กœ mod_copy๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : linux.org.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€