English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21392
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç IMP ÇÁ·Î±×·¥¿¡´Â DB ÆÄÀϰü·Ã SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
IMP(Internet Messaging Program)´Â Unix ½Ã½ºÅÛÀ» À§ÇØ PHP·Î ÀÛ¼ºµÈ À¥ ±â¹ÝÀÇ E-Mail Ŭ¶óÀÌ¾ðÆ® ÆÐŰÁöÀÌ´Ù. IMP 2.2.8 ¹öÀü°ú ±× ÀÌÀü ¹öÀüµé¿¡´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·Â µ¥ÀÌÅͰ¡ SQL Äõ¸®·Î Àü´ÞµÇ±â Àü¿¡ ¿Ã¹Ù¸£°Ô ÇÊÅ͵ÇÁö ¸øÇÏ¿© SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'mailbox.php3' ½ºÅ©¸³Æ®¿¡ SQL ¸í·ÉÀÌ Æ÷ÇÔµÈ Àß Á¶ÀÛÇÑ URLÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ÈÄÀ§ µ¥ÀÌÅÍ º£À̽º »óÀÇ µ¥ÀÌÅ͸¦ Ãß°¡, »èÁ¦, º¯Á¶Çϰųª ¶Ç´Â Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/unixfocus/5KP0S2K8UE.html
http://securitytracker.com/alerts/2003/Jan/1005904.html
http://marc.theaimsgroup.com/?l=bugtraq&m=104204786206563&w=2

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IMP 2.2.8 ¹öÀü°ú ±× ÀÌÀü ¹öÀüµé
Conectiva Linux 7.0, 8.0
Debian Linux 2.2, 3.0
SuSE Linux 7.3, 8.0, 8.1
Linux ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Horde À¥ »çÀÌÆ®·ÎºÎÅÍ IMP °¡Àå ÃֽйöÀü(3.1 ¶Ç´Â ±× ÀÌÈÄ ¹öÀü)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.horde.org/imp/

Debian GNU/LinuxÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¹® DSA-229-2 À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ IMP ÆÐŰÁö¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-229

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È °ø°í¹® SuSE-SA:2003:008 À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ IMP ÆÐŰÁö¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/advisories/suse_advisory-2862.html

Conectiva LinuxÀÇ °æ¿ì:
´ÙÀ½ Conectiva º¸¾È °ø°í¹® CLSA-2003:690 À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ IMP ÆÐŰÁö¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000690

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2003-0025 (CVE)
°ü·Ã URL 6559 (SecurityFocus)
°ü·Ã URL 11028 (ISS)