English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22174
À§Çèµµ 30
Æ÷Æ® 8000
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Macromedia JRunÀº Á¸ÀçÇÏÁö ¾Ê´Â .shtmlÀ» ÅëÇÑ ¼Ò½º ³ëÃâ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Macromedia JRunÀº JSP¿Í Java Servletµé·Î µÈ À¥ ¾îÇø®ÄÉÀÌ¼Ç °³¹ß µµ±¸ÀÌ´Ù. JRunÀº Server Side Includes (SSI)¸¦ Áö¿øÇÑ´Ù. SSI´Â À¥ °³¹ßÀÚ°¡ Á¤Àû(Static) HTML ÆÄÀÏ¿¡ ´Ù¾çÇÑ ÆÄÀϵéÀ» Æ÷ÇÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Æ÷ÇԵǾî¾ß ÇÒ º¯¼öµéÀÌ À¥ »çÀÌÆ® »ó¿¡¼­ ÇöÀç ½Ã°£ ȤÀº ÃÖÁ¾ ¼öÁ¤µÈ ³¯Â¥¿Í ½Ã°£ µîÀÌ µÉ ¼öµµ Àֱ⠶§¹®ÀÌ´Ù. µðÆúÆ®·Î SSI Çڵ鷯¿Í °áºÎµÈ ÆÄÀÏ È®ÀåÀÚ´Â .shtml ÀÌ´Ù.

JRun ¹öÀü 2.3.3, 3.0°ú 3.1Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Web root µð·ºÅ丮 ³»¿¡ ÀÖ´Â º¸È£¹Þ´Â ÆÄÀϵéÀÇ ¼Ò½ºÄڵ带 °¡Á®°¥ ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¾Ë·ÁÁø ÆÄÀÏÀ» Æ÷ÇÔÇÏ´Â Á¸ÀçÇÏÁö ¾Ê´Â .shtml ÆÄÀÏ¿¡ ´ëÇÑ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³»°Ô µÇ¸é È£½ºÆ®»óÀÇ Á¸ÀçÇÏ´Â ¾Ë·ÁÁø ÆÄÀÏÀÇ ³»¿ëµéÀ» ³ëÃâÇÑ´Ù. ÀÌ ¹®Á¦´Â SSI ÆäÀÌÁöµé¿¡ ´ëÇÑ ¿äûµéÀ» ó¸®ÇÏ´Â Server Side ±¸¼º¿ä¼Ò¿¡ ÀÖ´Â °áÇÔÀ¸·Î ÀÎÇÑ °á°úÀÌ´Ù. (JSP ½ºÅ©¸³Æ®µé°ú °°ÀÌ) ½ÇÇàÇü ¹®ÀåÀ¸·Î½á ¹ø¿ªµÇ¾îÁö´Â ÆÄÀϵéÀÌ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿äûµÈ´Ù¸é Áß¿äÇÑ ¼Ò½ºÄڵ尡 À¯ÃâµÉ ¼öµµ ÀÖ´Ù. ¶ÇÇÑ À¥ ¼­¹ö»ó¿¡ ¸ÅÇεǾî ÀÖÁö ¾ÊÀº ÀÓÀÇÀÇ Java ServletµéÀ» °ø°ÝÀÚµéÀÌ ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full
http://www.netcraft.com/security/public-advisories/2001-11.1.html
http://online.securityfocus.com/bid/3589

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
JRun 3.1 (all editions)
JRun 3.0 (all editions)
JRun 2.3.3 (all editions)
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ JRunÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
https://www.adobe.com/products/jrun/download/
°ü·Ã URL CVE-2001-0926 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)