English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25033
À§Çèµµ 30
Æ÷Æ® 1521, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç Oracle µ¥ÀÌÅͺ£À̽º ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â SOAP ¹× XML°ú °ü·ÃµÈ ¼­ºñ½º °ÅºÎ¿¡ Ãë¾àÇÏ´Ù.
µðÆúÆ®·Î XML°ú SOAP (Simple Object Access Protocol)´Â Oracle9i Application Server¿¡¼­ ÀÛµ¿ÇÏ°Ô µÇ¾î ÀÖÀ¸¸ç ¶ÇÇÑ Oracle HTTP Server°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é ÀÌ ¿É¼ÇµéÀº Oracle9i Database Server¿¡ µðÆúÆ®·Î ÀÛµ¿ÇÑ´Ù. ¾ÇÀÇÀûÀÎ DTDµé(Data Type Definitions)À» Æ÷ÇÔÇÑ XMLÀ» °¡Áø Àß Á¶ÀÛµÈ SOAP ¸Þ½ÃÁö¸¦ º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º ¼­¹ö¸¦ ÀÛµ¿ ÁßÁö½Ãų ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ Ãë¾àÁ¡Àº SOAP¿¡ ´ëÇÑ ÀÎÁõÀÌ ÀÛµ¿µÇ°í ÀÖÁö ¾Ê°Å³ª °ø°ÝÀÚ°¡ SOAP ¼­ºñ½ºµé¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Â °æ¿ì¿¡µµ ³ëÃâµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ OracleÀÇ ListenerÀÇ ¹öÀüÁ¤º¸¿¡¸¸ ÀÇÁ¸ÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.oracle.com/technetwork/topics/security/2004alert65-129518.pdf

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Oracle9i Application Server Release 1 1.0.2.2
Oracle Oracle9i Application Server Release 2 9.0.2.1 ÀÌÇÏ
Oracle Oracle9i Application Server Release 2 9.0.3.0
Oracle Oracle9i Application Server Release 2 9.0.3.1
Oracle Oracle9i Database Server Release 1 9.0.1.4
Oracle Oracle9i Database Server Release 2 9.2.0.2
¸ðµç Ç÷§Æû
ÇØ°áÃ¥ Oracle MetaLink À¥ »çÀÌÆ®ÀÎ http://metalink.oracle.com ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Oracle Database Server Release 2ÀÇ °¡Àå ÃֽйöÀü(9.2.0.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

-- ȤÀº --

´ÙÀ½ Oracle Security Alert #65¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.oracle.com/technetwork/topics/security/2004alert65-129518.pdf

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, SOAP ±â´ÉÀÌ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ´ÙÀ½ ¶óÀ̺귯¸®¸¦ °³¸íÇϰųª »èÁ¦ÇÔÀ¸·Î½á ÀÛµ¿ÁßÁö ½Ãų ¼öµµ ÀÖ´Ù:

[Oracle Home]/soap/lib.soap.jar
°ü·Ã URL CVE-2004-2244 (CVE)
°ü·Ã URL 9703,9705 (SecurityFocus)
°ü·Ã URL 15270 (ISS)