English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21456
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç TECH-NOTE¿¡´Â 'print.cgi' ½ºÅ©¸³Æ®¿¡ ÆÄÀÏ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
TECH-NOTE (Technote) ´Â À¥ »çÀÌÆ®¸¦ À§ÇØ Çѱ¹¿¡¼­ °³¹ßµÈ ÀαâÀÖ´Â °Ô½ÃÆÇ ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. TECH-NOTE 2000, 2001, Pro ¿¡´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇϵµ·Ï Çã¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ 'print.cgi' ½ºÅ©¸³Æ® »ó¿¡¼­ open() ÇÔ¼ö¸¦ È£ÃâÇÒ ¶§ Àü´ÞµÇ´Â »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ °Ë»çÇÏÁö ¸øÇϱ⠶§¹®ÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'board' ÆÄ¶ó¹ÌÅÍ¿¡ "/../" ¹®ÀÚ¿­À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL À» ¼­¹ö¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, À¥ ¼­¹ö »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇϰųª ÆÄÀϵéÀ» ÀÐÀ» ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/153007
http://beyonce.beyondsecurity.com/unixfocus/5ZP061535O.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
TECH-NOTE Inc., TECH-NOTE 2000
TECH-NOTE Inc., TECH-NOTE 2001
TECH-NOTE Inc., TECH-NOTE Pro
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½°ú °°ÀÌ ÀÌ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:

1. 'technote/print.cgi' ¼Ò½º¸¦ ¿­°í ÄÚµå '&parse;' ¶óÀÎÀ» ã´Â´Ù.
2. ´ÙÀ½ ¶óÀο¡ 'exit if($FORM{'img'}=~/\;|\%|\\|\.\.|\||\//);' Äڵ带 Ãß°¡ÇÑ´Ù.
°ü·Ã URL CVE-2001-0074 (CVE)
°ü·Ã URL 2155 (SecurityFocus)
°ü·Ã URL 5815 (ISS)