English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25048
À§Çèµµ 30
Æ÷Æ® 1521, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í Oracle Database ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ´ÙÁßÀÇ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Oracle8i and 9i Database ¼­¹öµéÀº ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ°¡ Oracle Database ¼­¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ÆÄÀϵéÀ» Àаųª ¾²°Å³ª ȤÀº °³¸í(rename)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Â ´ÙÁßÀÇ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ÆÄÀÏ Ã³¸® ÇÔ¼öµé·Î Àü´ÞµÈ ÆÄÀÏ¸í ±×¸®°í °æ·Î¸íµé¿¡ ´ëÇØ ¼öÇàµÈ ÀԷ°ª¿¡ ´ëÇÑ Å¸´ç¼º °ËÁõÀÇ °áÇÔÀ¸·Î ÀÎÇØ Á¸ÀçÇÏ´Â °ÍÀ¸·Î º¸°í µÇ¾î ÀÖ´Ù. ÀÌ´Â ¾ÇÀÇÀûÀÎ SQL ÁúÀǸ¦ ÅëÇØ Oracle µð·ºÅ丮 ¿ÀºêÁ§Æ®(object)¿¡ Á¤ÀǵǾî ÀÖ´Â µð·ºÅ丮ÀÇ ¿ÜºÎ¸¦ Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Oracle µ¥ÀÌÅͺ£À̽º ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securityfocus.com/archive/1/392527
http://www.argeniss.com/research/ARGENISS-ADV-030501.txt
http://www.petefinnigan.com/directory_traversal.pdf
http://www.oracle.com/technetwork/topics/security/cpu-jan-2005-advisory-129526.pdf
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Corporation, Oracle8i Database Server Any version
Oracle Corporation, Oracle9i Database Server Any version
Microsoft Windows Any version
Linux Any version
Unix Any version

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Database ¼­¹ö
ÇØ°áÃ¥ Oracle »ç´Â ÀÌ ¹®Á¦µéÀ» ÇØ°áÇÒ ¼ö ÀÖ´Â Critical Patch Update¸¦ ³»³õ¾Ò´Ù. ÀûÀýÇÑ ÆÐÄ¡ ȹµæ ¹× Àû¿ë¿¡ °üÇÑ Á¤º¸´Â ´ÙÀ½ 2005³â 1¿ù Oracle Critical Patch Update¿¡¼­ ãÀ» ¼ö ÀÖ´Ù:
http://www.oracle.com/technetwork/topics/security/cpu-jan-2005-advisory-129526.pdf

-- ȤÀº --

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î Directory Objectµé°ú UTL_FILE ÆÐŰÁö¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Á¦ÇÑÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 12749 (SecurityFocus)
°ü·Ã URL (ISS)