Ãë¾àÁ¡ID |
25411 |
À§Çèµµ |
40 |
Æ÷Æ® |
5432 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
DB |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ PostgreSQL ¹öÀüÀÌ 13.19 ÀÌÀüÀÇ 13, 14.16 ÀÌÀüÀÇ 14, 15.11 ÀÌÀüÀÇ 15, 16.7 ÀÌÀüÀÇ 16 ¶Ç´Â 17.3 ÀÌÀüÀÇ 17ÀÔ´Ï´Ù. µû¶ó¼ ´ÙÀ½°ú °°Àº Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.
- PostgreSQL libpq ÇÔ¼öÀÇ PQescapeLiteral(), PQescapeIdentifier(), PQescapeString() ¹× PQescapeStringConn()¿¡¼ ÀÎ¿ë ±¸¹®ÀÌ ÀûÀýÇÏ°Ô ÁßȵÇÁö ¾Ê¾Æ ƯÁ¤ »ç¿ë ÆÐÅÏ¿¡¼ µ¥ÀÌÅͺ£À̽º ÀÔ·Â Á¦°øÀÚ°¡ SQL »ðÀÔÀ» ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ƯÈ÷ SQL »ðÀÔÀº ¾ÖÇø®ÄÉÀ̼ÇÀÌ ÇÔ¼ö °á°ú¸¦ »ç¿ëÇÏ¿© PostgreSQL ´ëÈÇü Å͹̳ÎÀÎ psql¿¡ ´ëÇÑ ÀÔ·ÂÀ» ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù. ¸¶Âù°¡Áö·Î PostgreSQL ¸í·ÉÁÙ À¯Æ¿¸®Æ¼ ÇÁ·Î±×·¥¿¡¼ ÀÎ¿ë ±¸¹®ÀÌ ÀûÀýÇÏ°Ô ÁßȵÇÁö ¾Ê¾Æ client_encodingÀÌ BIG5ÀÌ°í server_encodingÀÌ EUC_TW ¶Ç´Â MULE_INTERNAL Áß ÇϳªÀÎ °æ¿ì ¸í·ÉÁÙ ÀμöÀÇ ¼Ò½º°¡ SQL »ðÀÔÀ» ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. PostgreSQL 17.3, 16.7, 15.11, 14.16 ¹× 13.19 ÀÌÀü ¹öÀüÀÌ ¿µÇâÀ» ¹Þ½À´Ï´Ù. (CVE-2025-1094)
* Âü°í »çÀÌÆ®: https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/
* ¿µÇâ¹Þ´Â Ç÷§Æû: PostgreSQL 15.11 ÀÌÀüÀÇ 15.x ¹öÀüµé Any operating system Any version |
ÇØ°áÃ¥ |
PostgreSQL À¥ ÆäÀÌÁöÀÎ https://www.postgresql.org/download/¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PostgreSQLÀÇ °¡Àå ÃֽŠ¹öÀü(15.11 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2025-1094 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|