English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21349
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â phpGroupWare ¹öÀü¿¡ µû¸£¸é, phpGroupWare¿¡´Â ´Ù¼öÀÇ Cross-Site Scripting Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
Joseph EngoÀÇ phpGroupWare ´Â ÀüÀÚ¿ìÆí, ͏°´õ, To-Do ¸ñ·Ï°ú °°Àº ±â´ÉÀ» Æ÷ÇÔÇÏ´Â PHP ·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ±×·ì¿þ¾î ½Ã½ºÅÛÀÌ´Ù. phpGroupWare 0.9.14.005 ÀÌÀüÀÇ ÀϺΠ¹öÀü¿¡´Â PHPGroupWare ¸ðµâµé¿¡ ÀÇÇØ »ç¿ëµÇ´Â Æû ÇÊµå »ó¿¡¼­ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© ´Ù¼öÀÇ Cross-Site Scripting Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ® Äڵ带 Æ÷ÇÔÇØ¼­ Àß Á¶ÀÛµÈ URL ¸µÅ©¸¦ »ý¼ºÇÏ°í ´ë»ó »ç¿ëÀÚ°¡ À̸¦ Ŭ¸¯Çϵµ·Ï À¯µµÇÑ´Ù. ÀÏ´Ü URL ¸µÅ©°¡ Ŭ¸¯µÇ¸é, »ðÀÔµÈ ÄÚµåµéÀº ´ë»ó »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ ½ÇÇàµÉ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© »ç¿ëÀÚÀÇ ÄíŰ(cookie) ±â¹Ý ÀÎÁõ ½Å¿ë Á¤º¸µéÀ» ÈÉÄ¥ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç phpGroupWare ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-07/0022.html
http://www.osvdb.org/2243

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpGroupWare 0.9.14.003
phpGroupWare 0.9.13
phpGroupWare 0.9.12
Conectiva Linux 7.0, 8.0, 9.0
Debian Linux 3.0
Mandrake Linux 8.2, 9.0, 9.1, Corporate Server 2.1
Linux Any version
Windows Any version
Unix Any version
ÇØ°áÃ¥ phpGroupWare ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://prdownloads.sourceforge.net/phpgroupware/ ¿¡¼­ phpGroupWareÀÇ °¡Àå ÃֽйöÀü(0.9.14.005 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Mandrake LinuxÀÇ °æ¿ì,
MandrakeSoft º¸¾È ±Ç°í¹® MDKSA-2003:077, http://www.mandriva.com/en/support/security/advisories/ ¿¡¼­ MDKSA-2003:077¸¦ Âü°íÇÏ¿©phpGroupWareÀÇ °¡Àå ÃֽйöÀüÀÇ ÆÐŰÁö¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì,
Debian º¸¾È ±Ç°í¹® DSA-365-1, http://www.debian.org/security/2003/dsa-365 ¿¡¼­ phpGroupWareÀÇ °¡Àå ÃֽйöÀü(0.9.14-0.RC3.2.woody2 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

´Ù¸¥ ¹èÆ÷ÆÇÀÇ °æ¿ì,
¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ¼­´Â ÇØ´ç Á¦Ç° Á¦Á¶»ç¿¡ ¹®ÀÇÇÑ´Ù.
°ü·Ã URL CVE-2003-0504 (CVE)
°ü·Ã URL 8088 (SecurityFocus)
°ü·Ã URL 12497 (ISS)