Ãë¾àÁ¡ID |
22270 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö´Â 4.3.7 ÀÌÇÏÀÇ PHP 4.3ÀÇ ¹öÀüÀ» »ç¿ë ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³´Ù. PHP´Â À¥ °³¹ß¿¡ ÀûÇÕÇϰí HTML¿¡ ÀÓº£µðµå(embedded) µÉ ¼ö ÀÖ´Â ³Î¸® »ç¿ë ÁßÀÎ ¹ü¿ë ½ºÅ©¸³ÆÃ ¾ð¾îÀÌ´Ù. 4.3.7 ±îÁöÀÇ PHP 4.3.x, ±×¸®°í 5.0.0RC3±îÁöÀÇ 5.x´Â ´ÙÀ½°ú °°Àº µÎ °¡Áö Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù:
1. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Microsoft ÀÎÅÍ³Ý ÀͽºÇ÷η¯¿Í Safari À¥ ºê¶ó¿ìÀúµé¿¡ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® ű׵éÀ» »ðÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ´Â strip_tag ÇÔ¼ö ³»¿¡ HTML ű׵éÀ» ´Ù·ç´Â ¹æ¹ý »óÀÇ ¿À·ù·Î ÀÎÇØ ¹ß»ýÇÑ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇØ Cross-Site Scripting°ú °°Àº ¿©·¯ °¡Áö °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù. 2. register_globals°¡ »ç¿ë ÁßÀÎ °æ¿ì¿Í °°Àº ƯÁ¤ Á¶°Ç ÇÏ¿¡¼, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼¹ö »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. ¸¸¾à memory_limit ±â´ÉÀÌ ÀÛµ¿ ÁßÀ̶ó¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â memory_limit Á¾·á ¿äûÀ» È£ÃâÇϱâ À§ÇÑ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³¾ ¼ö ÀÖ´Ù. ÀÌ À§ÇèÇÑ ÀÎÅÍ·´Æ®·Î ÀÎÇØ PHP ¼¹ö¿¡´Â ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0576.html http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0577.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Internet Explorer Safari Web browser PHP 4.3.7 ÀÌÇÏ PHP5 5.0.0RC3 ÀÌÇÏ Microsoft Windows Any version Unix Any version Linux Any version |
ÇØ°áÃ¥ |
PHP4ÀÇ °æ¿ì: PHP À¥ »çÀÌÆ®, http://www.php.net ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHP4ÀÇ °¡Àå ÃֽйöÀü(4.3.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
PHP5ÀÇ °æ¿ì: PHP À¥ »çÀÌÆ®, http://www.php.net ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHP5ÀÇ °¡Àå ÃֽйöÀü(2004³â 7¿ù 13ÀÏÀÚ 5.0.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:068À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200407-13À» ÂüÁ¶ÇÏ¿© phpÀÇ °¡Àå ÃֽйöÀü(4.3.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml
±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2004-0594,CVE-2004-0595 (CVE) |
°ü·Ã URL |
10724,10725 (SecurityFocus) |
°ü·Ã URL |
16693,16692 (ISS) |
|