Ãë¾àÁ¡ID |
25027 |
À§Çèµµ |
40 |
Æ÷Æ® |
3306 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
DB |
»ó¼¼¼³¸í |
ÇØ´ç MySQL ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ºÎÀûÀýÇÑ ÆÐ½º¿öµå 󸮷ΠÀÎÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. MySQLÀº ´Ù¼öÀÇ À¥ »çÀÌÆ®µéÀ» À§ÇÑ ÈÄÀ§(back-end) µ¥ÀÌÅͺ£À̽º ¼¹ö·Î ³Î¸® »ç¿ëµÇ´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ü°èÇü µ¥ÀÌÅͺ£À̽º ¼¹öÀÌ´Ù. ÀÌ MySQL ¼¹öÀÇ ÀϺΠ¹öÀüµé¿¡¼´Â MySQL »ç¿ëÀÚ ÆÐ½º¿öµå¸¦ ó¸®ÇÏ´Â °úÁ¤¿¡¼ ÀûÀýÇÑ °æ°è °Ë»ç°¡ ÀÌ·ç¾îÁöÁö ¾Ê¾Æ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº 16 ¹®ÀÚ ÀÌ»óÀÇ ÆÐ½º¿öµå¸¦ Àü´ÞÇÔÀ¸·Î½á, ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í MySQL ¼¹ö °èÁ¤ ±ÇÇÑÀ¸·Î ¼¹ö »ó¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ MySQL ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-09/0188.html http://www.kb.cert.org/vuls/id/516492
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: MySQL 3.0.57 ¿Í ±× ÀÌÀü ¹öÀüµé MySQL 4.0.14 ¿Í ±× ÀÌÀü ¹öÀüµé Conectiva Linux 7.0, 8.0, 9.0 Mandrake Linux 8.2, 9.0, 9.1, Corporate Server 2.1 Debian Linux 3.0 EnGarde Secure Linux 1.0.1, Community Edition, Professional Edition OpenPKG 1.2, 1.3, CURRENT Unix Any version Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ÀÇ MySQL À¥ ¼¹ö¸¦ ÂüÁ¶ÇÏ¿© MySQL ÀÇ °¡Àå ÃֽйöÀü(4.0.15 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mysql.com/downloads/mysql-4.0.html
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-381-1À» ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽйöÀü(3.23.49-8.5 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2003/dsa-381
EnGarde Secure Linux Community Edition°ú Professional EditionÀÇ °æ¿ì: ´ÙÀ½ Guardian Digital º¸¾È ±Ç°í¾È ESA-20030918-025¸¦ ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽŠÆÐŰÁö(3.23.56-1.0.24 ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.linuxsecurity.com/content/view/105387/170/
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft º¸¾È ±Ç°í¾È MDKSA-2003:094:MySQLÀ» ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽŠÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
±âŸ: ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ »çÀÌÆ®¿¡¼ MySQL 4.0.14¿¡ Àû¿ëÇÒ ¼ö ÀÖ´Â ºñ°ø½ÄÀûÀÎ ÆÐÄ¡¸¦ ±¸ÇÒ ¼ö ÀÖ´Ù: http://downloads.securityfocus.com/vulnerabilities/patches/MySQL4.0.14.Patch |
°ü·Ã URL |
CVE-2003-0780 (CVE) |
°ü·Ã URL |
8590 (SecurityFocus) |
°ü·Ã URL |
13153 (ISS) |
|