Ãë¾àÁ¡ID |
22291 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö´Â 4.3.9 ȤÀº 5.0.2 º¸´Ù ´õ ¿À·¡µÈ PHPÀÇ ¹öÀüÀ» °¡µ¿ ÁßÀÌ´Ù. PHP´Â À¥ °³¹ß¿¡ ÀûÇÕÇϰí HTML¿¡ ÀÓº£µðµå(embedded) µÉ ¼ö ÀÖ´Â ³Î¸® »ç¿ë ÁßÀÎ ¹ü¿ë ½ºÅ©¸³ÆÃ ¾ð¾îÀÌ´Ù. 4.3.8 ±îÁöÀÇ PHP 4.x.x, ±×¸®°í 5.0.1±îÁöÀÇ 5.x´Â »ç¿ëÀÚ Á¦°ø ÆÄÀϸí ÀÔ·Â °ªÀ» ÀûÀýÇÏ°Ô °É·¯ ³»Áö ¸øÇÏ´Â PHP ¾îÇø®ÄÉÀ̼ÇÀÇ µÎ °¡Áö ¹ö±×µé·Î ÀÎÇÑ ÀÓÀÇÀÇ ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. PHP¿¡ ÀÖ´Â ÀÌ µÎ °¡Áö ¹ö±×µéÀº ¸Þ¸ð¸®ÀÇ ºÎºÐÀûÀÎ ³ëÃâ°ú ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ÀÓÀÇÀÇ À§Ä¡·ÎÀÇ ÆÄÀÏ ¾÷·Îµå¸¦ Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ù¹øÂ° Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¸Þ¸ð¸®ÀÇ ³»¿ëµéÀ» º¼ ¼ö ÀÖ´Ù. ÆÄÀÏ ¾÷·Îµå¸¦ Á¦°øÇØ ÁÖ´Â ½ºÅ©¸³Æ®¸¦ °¡Áø ¼¹ö »ó¿¡¼ °ø°ÝÀÚ´Â µÎ¹øÂ° Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ÀÓÀÇÀÇ À§Ä¡¿¡ ÆÄÀϵéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ´Ù. HTTP ¼¹ö°¡ HTTP ¾×¼¼½º °¡´É À§Ä¡¿¡ ¾²±â °¡´ÉÇϵµ·Ï Çã¿ëÇØ ³õÀº ½Ã½ºÅÛµé »ó¿¡¼´Â ÀÌ Ãë¾àÁ¡ÀÌ °á°úÀûÀ¸·Î HTTP ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ¸í·ÉµéÀÇ ¿ø°Ý ½ÇÇàÀ» Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/376865 http://www.securityfocus.com/archive/1/375370
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHP 4.3.9 ÀÌÀüÀÇ ¹öÀüµé PHP 5.0.2 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
PHP ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://www.php.net/downloads.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHPÀÇ °¡Àå ÃֽйöÀü(4.3.9 ȤÀº 5.0.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200410-04¸¦ ÂüÁ¶ÇÏ¿© PHPÀÇ °¡Àå ÃֽйöÀü(4.3.9 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200410-04.xml
±âŸ: ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2004-0959
CVE-2004-0959 (CVE) |
°ü·Ã URL |
11190 (SecurityFocus) |
°ü·Ã URL |
17392 (ISS) |
|