Ãë¾àÁ¡ID |
21271 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç CVSWeb CGIÀÇ ¹öÀü¿¡ µû¸£¸é CGI´Â ¾ÈÀüÇÏÁö ¸øÇÑ perl "open" Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Henner Zeller CVSWebÀº ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 °øÀ¯Çϰí CVS ÀúÀå¼ÒÀÇ ³»¿ëÀ» ã¾Æº¸´Âµ¥ »ç¿ëµÈ´Ù. CVSWeb ÆÐŰÁöÀÇ 1.85 ÀÌÇÏ ¹öÀüµéÀº CVS ÀúÀå¼Ò¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» °¡Áø ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ CGI ÇÁ·Î±×·¥À» ÅëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Cvsweb.cgi ÇÁ·Î±×·¥¿¡ ÀÖ´Â Perl ÄÚµå´Â open() ÇÔ¼ö¸¦ ¾ÈÀüÇÏÁö ¸øÇÏ°Ô È£ÃâÇÑ´Ù. °ø°ÝÀÚ´Â ShellÀÇ Meta ¹®ÀÚµéÀ» Æ÷ÇÔÇÑ ÆÄÀϸíÀ» »ý¼ºÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ Shell Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/69942
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Henner Zeller CVSWeb 1.85 ÀÌÇÏ UNIX Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ HenÀÇ cvsweb CVS Repository¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â CVSWebÀÇ °¡Àå ÃֽйöÀü(1.86 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.tucows.com/preview/26757/CVSweb
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2000:019¸¦ ÂüÁ¶ÇÏ¿© CVSWebÀÇ °¡Àå ÃֽйöÀü(1.80-3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
Debian GNU/LinuxÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory 20000719b¸¦ ÂüÁ¶ÇÏ¿© CVSWebÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2000/20000719b
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2000-0670 (CVE) |
°ü·Ã URL |
1469 (SecurityFocus) |
°ü·Ã URL |
4925 (ISS) |
|