Ãë¾àÁ¡ID |
22174 |
À§Çèµµ |
30 |
Æ÷Æ® |
8000 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Macromedia JRunÀº Á¸ÀçÇÏÁö ¾Ê´Â .shtmlÀ» ÅëÇÑ ¼Ò½º ³ëÃâ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Macromedia JRunÀº JSP¿Í Java Servletµé·Î µÈ À¥ ¾îÇø®ÄÉÀÌ¼Ç °³¹ß µµ±¸ÀÌ´Ù. JRunÀº Server Side Includes (SSI)¸¦ Áö¿øÇÑ´Ù. SSI´Â À¥ °³¹ßÀÚ°¡ Á¤Àû(Static) HTML ÆÄÀÏ¿¡ ´Ù¾çÇÑ ÆÄÀϵéÀ» Æ÷ÇÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Æ÷ÇԵǾî¾ß ÇÒ º¯¼öµéÀÌ À¥ »çÀÌÆ® »ó¿¡¼ ÇöÀç ½Ã°£ ȤÀº ÃÖÁ¾ ¼öÁ¤µÈ ³¯Â¥¿Í ½Ã°£ µîÀÌ µÉ ¼öµµ Àֱ⠶§¹®ÀÌ´Ù. µðÆúÆ®·Î SSI Çڵ鷯¿Í °áºÎµÈ ÆÄÀÏ È®ÀåÀÚ´Â .shtml ÀÌ´Ù.
JRun ¹öÀü 2.3.3, 3.0°ú 3.1Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Web root µð·ºÅ丮 ³»¿¡ ÀÖ´Â º¸È£¹Þ´Â ÆÄÀϵéÀÇ ¼Ò½ºÄڵ带 °¡Á®°¥ ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¾Ë·ÁÁø ÆÄÀÏÀ» Æ÷ÇÔÇÏ´Â Á¸ÀçÇÏÁö ¾Ê´Â .shtml ÆÄÀÏ¿¡ ´ëÇÑ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³»°Ô µÇ¸é È£½ºÆ®»óÀÇ Á¸ÀçÇÏ´Â ¾Ë·ÁÁø ÆÄÀÏÀÇ ³»¿ëµéÀ» ³ëÃâÇÑ´Ù. ÀÌ ¹®Á¦´Â SSI ÆäÀÌÁöµé¿¡ ´ëÇÑ ¿äûµéÀ» ó¸®ÇÏ´Â Server Side ±¸¼º¿ä¼Ò¿¡ ÀÖ´Â °áÇÔÀ¸·Î ÀÎÇÑ °á°úÀÌ´Ù. (JSP ½ºÅ©¸³Æ®µé°ú °°ÀÌ) ½ÇÇàÇü ¹®ÀåÀ¸·Î½á ¹ø¿ªµÇ¾îÁö´Â ÆÄÀϵéÀÌ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿äûµÈ´Ù¸é Áß¿äÇÑ ¼Ò½ºÄڵ尡 À¯ÃâµÉ ¼öµµ ÀÖ´Ù. ¶ÇÇÑ À¥ ¼¹ö»ó¿¡ ¸ÅÇεǾî ÀÖÁö ¾ÊÀº ÀÓÀÇÀÇ Java ServletµéÀ» °ø°ÝÀÚµéÀÌ ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full http://www.netcraft.com/security/public-advisories/2001-11.1.html http://online.securityfocus.com/bid/3589
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: JRun 3.1 (all editions) JRun 3.0 (all editions) JRun 2.3.3 (all editions) |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ JRunÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. https://www.adobe.com/products/jrun/download/ |
°ü·Ã URL |
CVE-2001-0926 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|