English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21271
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç CVSWeb CGIÀÇ ¹öÀü¿¡ µû¸£¸é CGI´Â ¾ÈÀüÇÏÁö ¸øÇÑ perl "open" Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Henner Zeller CVSWebÀº ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 °øÀ¯Çϰí CVS ÀúÀå¼ÒÀÇ ³»¿ëÀ» ã¾Æº¸´Âµ¥ »ç¿ëµÈ´Ù. CVSWeb ÆÐŰÁöÀÇ 1.85 ÀÌÇÏ ¹öÀüµéÀº CVS ÀúÀå¼Ò¿¡ ´ëÇÑ ¾²±â ±ÇÇÑÀ» °¡Áø ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ CGI ÇÁ·Î±×·¥À» ÅëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Cvsweb.cgi ÇÁ·Î±×·¥¿¡ ÀÖ´Â Perl ÄÚµå´Â open() ÇÔ¼ö¸¦ ¾ÈÀüÇÏÁö ¸øÇÏ°Ô È£ÃâÇÑ´Ù. °ø°ÝÀÚ´Â ShellÀÇ Meta ¹®ÀÚµéÀ» Æ÷ÇÔÇÑ ÆÄÀϸíÀ» »ý¼ºÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ Shell Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/69942

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Henner Zeller CVSWeb 1.85 ÀÌÇÏ
UNIX Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ HenÀÇ cvsweb CVS Repository¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â CVSWebÀÇ °¡Àå ÃֽйöÀü(1.86 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.tucows.com/preview/26757/CVSweb

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2000:019¸¦ ÂüÁ¶ÇÏ¿© CVSWebÀÇ °¡Àå ÃֽйöÀü(1.80-3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

Debian GNU/LinuxÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory 20000719b¸¦ ÂüÁ¶ÇÏ¿© CVSWebÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2000/20000719b

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2000-0670 (CVE)
°ü·Ã URL 1469 (SecurityFocus)
°ü·Ã URL 4925 (ISS)