Ãë¾àÁ¡ID |
21456 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç TECH-NOTE¿¡´Â 'print.cgi' ½ºÅ©¸³Æ®¿¡ ÆÄÀÏ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. TECH-NOTE (Technote) ´Â À¥ »çÀÌÆ®¸¦ À§ÇØ Çѱ¹¿¡¼ °³¹ßµÈ ÀαâÀÖ´Â °Ô½ÃÆÇ ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. TECH-NOTE 2000, 2001, Pro ¿¡´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇϵµ·Ï Çã¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ 'print.cgi' ½ºÅ©¸³Æ® »ó¿¡¼ open() ÇÔ¼ö¸¦ È£ÃâÇÒ ¶§ Àü´ÞµÇ´Â »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ °Ë»çÇÏÁö ¸øÇϱ⠶§¹®ÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'board' ÆÄ¶ó¹ÌÅÍ¿¡ "/../" ¹®ÀÚ¿À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL À» ¼¹ö¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, À¥ ¼¹ö »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇϰųª ÆÄÀϵéÀ» ÀÐÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/153007 http://beyonce.beyondsecurity.com/unixfocus/5ZP061535O.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: TECH-NOTE Inc., TECH-NOTE 2000 TECH-NOTE Inc., TECH-NOTE 2001 TECH-NOTE Inc., TECH-NOTE Pro Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½°ú °°ÀÌ ÀÌ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
1. 'technote/print.cgi' ¼Ò½º¸¦ ¿°í ÄÚµå '&parse;' ¶óÀÎÀ» ã´Â´Ù. 2. ´ÙÀ½ ¶óÀο¡ 'exit if($FORM{'img'}=~/\;|\%|\\|\.\.|\||\//);' Äڵ带 Ãß°¡ÇÑ´Ù. |
°ü·Ã URL |
CVE-2001-0074 (CVE) |
°ü·Ã URL |
2155 (SecurityFocus) |
°ü·Ã URL |
5815 (ISS) |
|