English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22270
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â 4.3.7 ÀÌÇÏÀÇ PHP 4.3ÀÇ ¹öÀüÀ» »ç¿ë ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³­´Ù.
PHP´Â À¥ °³¹ß¿¡ ÀûÇÕÇϰí HTML¿¡ ÀÓº£µðµå(embedded) µÉ ¼ö ÀÖ´Â ³Î¸® »ç¿ë ÁßÀÎ ¹ü¿ë ½ºÅ©¸³ÆÃ ¾ð¾îÀÌ´Ù. 4.3.7 ±îÁöÀÇ PHP 4.3.x, ±×¸®°í 5.0.0RC3±îÁöÀÇ 5.x´Â ´ÙÀ½°ú °°Àº µÎ °¡Áö Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù:

1. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Microsoft ÀÎÅÍ³Ý ÀͽºÇ÷η¯¿Í Safari À¥ ºê¶ó¿ìÀúµé¿¡ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® ű׵éÀ» »ðÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ´Â strip_tag ÇÔ¼ö ³»¿¡ HTML ű׵éÀ» ´Ù·ç´Â ¹æ¹ý »óÀÇ ¿À·ù·Î ÀÎÇØ ¹ß»ýÇÑ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇØ Cross-Site Scripting°ú °°Àº ¿©·¯ °¡Áö °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
2. register_globals°¡ »ç¿ë ÁßÀÎ °æ¿ì¿Í °°Àº ƯÁ¤ Á¶°Ç ÇÏ¿¡¼­, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¼­¹ö »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. ¸¸¾à memory_limit ±â´ÉÀÌ ÀÛµ¿ ÁßÀ̶ó¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â memory_limit Á¾·á ¿äûÀ» È£ÃâÇϱâ À§ÇÑ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³¾ ¼ö ÀÖ´Ù. ÀÌ À§ÇèÇÑ ÀÎÅÍ·´Æ®·Î ÀÎÇØ PHP ¼­¹ö¿¡´Â ÀÓÀÇÀÇ Äڵ尡 ½ÇÇàµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0576.html
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0577.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Internet Explorer
Safari Web browser
PHP 4.3.7 ÀÌÇÏ
PHP5 5.0.0RC3 ÀÌÇÏ
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ PHP4ÀÇ °æ¿ì:
PHP À¥ »çÀÌÆ®, http://www.php.net ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PHP4ÀÇ °¡Àå ÃֽйöÀü(4.3.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

PHP5ÀÇ °æ¿ì:
PHP À¥ »çÀÌÆ®, http://www.php.net ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PHP5ÀÇ °¡Àå ÃֽйöÀü(2004³â 7¿ù 13ÀÏÀÚ 5.0.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:068À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200407-13À» ÂüÁ¶ÇÏ¿© phpÀÇ °¡Àå ÃֽйöÀü(4.3.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0594,CVE-2004-0595 (CVE)
°ü·Ã URL 10724,10725 (SecurityFocus)
°ü·Ã URL 16693,16692 (ISS)