English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22215
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç ColdFusion MX ¼­¹ö´Â RDS ¼­ºñ½º¸¦ ÅëÇÑ ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
ColdFusion RDS´Â °³¹ßÀÚµéÀÌ ¿ø°ÝÁö ÆÄÀϰú µ¥ÀÌÅÍ ¼Ò½ºµé, ±×¸®°í Debug CFML Äڵ带 ¾ÈÀüÇÏ°Ô ¾×¼¼½ºÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. °³¹ßÀÚµéÀº ColdFusion Studio, Homesite+, ±×¸®°í Dreamweaver MX¸¦ ÅëÇØ RDS¸¦ »ç¿ëÇÏ¿© HTTP Á¢¼ÓÀ» ÀÌ¿ëÇÑ ¿ø°ÝÁö ColdFusion °³¹ß ¼­¹ö¿¡ ÀÖ´Â ÆÄÀϵé°ú µ¥ÀÌÅͺ£À̽ºµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. ÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖ´Ù¸é RDS´Â ¿ø°ÝÁö °³¹ßÀÚ¸¦ ÀÎÁõÇÒ ¼ö ÀÖ´Â ÆÐ½º¿öµå¸¦ ÇÊ¿ä·Î ÇÑ´Ù.
ù¹øÂ° Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ ColdFusion ¼­¹ö¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ» (Put ±×¸®°í Get) ¾×¼¼½ºÇÏ¿© Ãë¾àÇÑ À¥ »çÀÌÆ®ÀÇ ÀÚ¿øµéÀ» Àç¼³Á¤ÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù.
µÎ¹øÂ° Ãë¾àÁ¡Àº µðÆúÆ®·Î RDS´Â ÀÎÁõÀ» À§ÇÑ ÆÐ½º¿öµå¸¦ ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â °Í(Null ÆÐ½º¿öµå)ÀÌ´Ù. ÀÌ ¶§¹®¿¡ RDS¿Í ȣȯÇÏ´Â °³¹ß ¾îÇø®ÄÉÀ̼ÇÀ» °¡Áø ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ ÆÐ½º¿öµå ¾øÀÌ ÀÎÁõÀ» ¹Þ¾Æ RDS°¡ ÀÛµ¿ÇÏ´Â ColdFusion ¼­¹ö¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù.
¼¼¹øÂ° Ãë¾àÁ¡Àº RDS ÆÐ½º¿öµåÀÌ ¼³Á¤µÇ¾î ÀÖÀ» ¶§, ÆÐ½º¿öµå°¡ ¾ÏȣȭµÇÁö ¾ÊÀº ÅØ½ºÆ®·Î Àü¼ÛµÇ¾î Áø´Ù´Â °ÍÀÌ´Ù.

* Âü°í »çÀÌÆ®:
http://sec.angrypacket.com/advisories/0006_AP.CF-rds-dump.txt
http://www.securitytracker.com/alerts/2003/Jul/1007124.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû
Macromedia ColdFusion Server MX Professional
Macromedia ColdFusion Server MX Enterprise
Macromedia ColdFusion Server MX Developer
Macromedia ColdFusion Server MX 6.0
Microsoft Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç·Î½á´Â ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ³ª¿ÍÀÖÁö ¾Ê´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 8109,8110 (SecurityFocus)
°ü·Ã URL 12569 (ISS)