Ãë¾àÁ¡ID |
22241 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç thttpd HTTP ¼¹ö´Â 404 ¿¡·¯ ÆäÀÌÁö¿¡ Cross-Site Scripting Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Acme Labs¿¡ ÀÇÇØ °³¹ßµÈ thttpd´Â ´ëºÎºÐÀÇ Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼ ÀÌ¿ë °¡´ÉÇÑ ¹«·á À¥ ¼¹ö µ¥¸óÀÌ´Ù. Thttpd ¹öÀü 2.20b ±×¸®°í ´Ù¸¥ ÀϺΠ¹öÀüµéÀº ¿¡·¯ ÆäÀÌÁöµéÀ» »ý¼ºÇÒ ¶§ URLµéÀÌ ½ºÅ©¸³Æ® ¸í·ÉµéÀ» Æ÷ÇÔÇϰí ÀÖ´Â Áö¸¦ üũÇÏÁö ¾Ê´Â´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URL ¸µÅ©¸¦ »ý¼ºÇÒ ¼ö ÀÖ´Ù. ¸µÅ©°¡ ÀÏ´Ü Å¬¸¯µÇ¸é, ¿¡·¯ ¸Þ½ÃÁö°¡ µð½ºÇ÷¹ÀÌµÇ¸é¼ È£½ºÆÃÇØ ÁÖ´Â »çÀÌÆ®ÀÇ ±ÇÇÑÀ» °¡Áö°í Èñ»ýÀÚÀÇ À¥ ºê¶ó¿ìÀú¿¡¼ Á¶ÀÛÇÑ ½ºÅ©¸³Æ®°¡ ½ÇÇàµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/vuln-dev/2002-q2/0155.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: thttpd 2.20b thttpd 2.20c Unix Any version Linux Any version |
ÇØ°áÃ¥ |
ÀÌ °áÇÔ¿¡ ´ëÇÑ ÆÐÄ¡´Â ±¸ÇÒ ¼ö ¾ø´Ù. ´ÙÀ½ thttpd À¥ »çÀÌÆ®¿¡¼ thttpdÀÇ °¡Àå ÃֽйöÀü(2.24 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.acme.com/software/thttpd/ |
°ü·Ã URL |
CVE-2002-0733 (CVE) |
°ü·Ã URL |
4601 (SecurityFocus) |
°ü·Ã URL |
9029 (ISS) |
|