English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25027
À§Çèµµ 40
Æ÷Æ® 3306
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç MySQL ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ºÎÀûÀýÇÑ ÆÐ½º¿öµå 󸮷ΠÀÎÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
MySQLÀº ´Ù¼öÀÇ À¥ »çÀÌÆ®µéÀ» À§ÇÑ ÈÄÀ§(back-end) µ¥ÀÌÅͺ£À̽º ¼­¹ö·Î ³Î¸® »ç¿ëµÇ´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ü°èÇü µ¥ÀÌÅͺ£À̽º ¼­¹öÀÌ´Ù. ÀÌ MySQL ¼­¹öÀÇ ÀϺΠ¹öÀüµé¿¡¼­´Â MySQL »ç¿ëÀÚ ÆÐ½º¿öµå¸¦ ó¸®ÇÏ´Â °úÁ¤¿¡¼­ ÀûÀýÇÑ °æ°è °Ë»ç°¡ ÀÌ·ç¾îÁöÁö ¾Ê¾Æ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº 16 ¹®ÀÚ ÀÌ»óÀÇ ÆÐ½º¿öµå¸¦ Àü´ÞÇÔÀ¸·Î½á, ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í MySQL ¼­¹ö °èÁ¤ ±ÇÇÑÀ¸·Î ¼­¹ö »ó¿¡¼­ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ MySQL ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-09/0188.html
http://www.kb.cert.org/vuls/id/516492

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MySQL 3.0.57 ¿Í ±× ÀÌÀü ¹öÀüµé
MySQL 4.0.14 ¿Í ±× ÀÌÀü ¹öÀüµé
Conectiva Linux 7.0, 8.0, 9.0
Mandrake Linux 8.2, 9.0, 9.1, Corporate Server 2.1
Debian Linux 3.0
EnGarde Secure Linux 1.0.1, Community Edition, Professional Edition
OpenPKG 1.2, 1.3, CURRENT
Unix Any version
Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ÀÇ MySQL À¥ ¼­¹ö¸¦ ÂüÁ¶ÇÏ¿© MySQL ÀÇ °¡Àå ÃֽйöÀü(4.0.15 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mysql.com/downloads/mysql-4.0.html

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-381-1À» ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽйöÀü(3.23.49-8.5 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-381

EnGarde Secure Linux Community Edition°ú Professional EditionÀÇ °æ¿ì:
´ÙÀ½ Guardian Digital º¸¾È ±Ç°í¾È ESA-20030918-025¸¦ ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽŠÆÐŰÁö(3.23.56-1.0.24 ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/105387/170/

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft º¸¾È ±Ç°í¾È MDKSA-2003:094:MySQLÀ» ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽŠÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

±âŸ:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ »çÀÌÆ®¿¡¼­ MySQL 4.0.14¿¡ Àû¿ëÇÒ ¼ö ÀÖ´Â ºñ°ø½ÄÀûÀÎ ÆÐÄ¡¸¦ ±¸ÇÒ ¼ö ÀÖ´Ù:
http://downloads.securityfocus.com/vulnerabilities/patches/MySQL4.0.14.Patch
°ü·Ã URL CVE-2003-0780 (CVE)
°ü·Ã URL 8590 (SecurityFocus)
°ü·Ã URL 13153 (ISS)