English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25037
À§Çèµµ 40
Æ÷Æ® 3306
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç MySQL ¼­¹öÀÇ ¹öÀüÀº 4.0.21 º¸´Ù ³·´Ù.
MySQL 4.0.20 ÀÌÇÏÀÇ ¹öÀüµé¿¡ ÀÖ´Â mysqlhotcopy ½ºÅ©¸³Æ®´Â ¾ÈÀüÇÏÁö ¾ÊÀº Àӽà ÆÄÀÏ »ý¼º Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ´Â ¾îÇø®ÄÉÀ̼ǿ¡ ÀÇÇØ »ý¼ºµÈ Àӽà ÆÄÀϵéÀÌ ¿¹»ó °¡´ÉÇÑ ÆÄÀϸíµéÀ» »ç¿ëÇϰí Àֱ⠶§¹®ÀÌ´Ù. ÀÌ ¹®Á¦´Â 'scp' ¸Þ½îµå(method)¿¡¼­ ±× ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¶§ ¹ß»ýÇÑ´Ù. ·ÎÄà °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿¹»ó °¡´ÉÇÑ ÆÄÀϵé·ÎºÎÅÍÀÇ Symbolic ¸µÅ©µéÀ» »ý¼ºÇÏ¿© ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» »ý¼ºÇϰųª µ¤¾î¾µ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç MySQL ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû
MySQL AB, MySQL 4.0.20 ÀÌÇÏ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ MySQL À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â MySQLÀÇ °¡Àå ÃֽйöÀü(4.0.21 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://dev.mysql.com/downloads/mysql/4.0.html

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-540-1À» ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽйöÀü(3.23.49-8.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-540

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200409-02¸¦ ÂüÁ¶ÇÏ¿© MySQLÀÇ °¡Àå ÃֽйöÀü(4.0.20-r1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200409-02.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0457 (CVE)
°ü·Ã URL 10969 (SecurityFocus)
°ü·Ã URL 17030 (ISS)