English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28647
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í Opera À¥ ºê¶ó¿ìÀúÀÇ ¹öÀü¿¡ µû¸£¸é Opera¿¡´Â location °´Ã¼ÀÇ Cross-Domain Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Opera´Â ´ÙÁßÀÇ ¿î¿µÃ¼Á¦ ¿ëÀ¸·Î Opera Software »ç¿¡ ÀÇÇØ °³¹ßµÈ À¥ ºê¶ó¿ìÀúÀÌ´Ù. Opera 7.53 ÀÌÇÏÀÇ ¹öÀüµéÀº Location °´Ã¼(Object)¿¡ ´ëÇÑ ¾²±â(Write) ¾×¼¼½º¸¦ ¿ÏÀüÈ÷ Â÷´ÜÇÏÁö ¸øÇÑ´Ù. ÀÌ °áÇÔÀº »ç¿ëÀÚ°¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ¸Þ½îµå(Method)µéÀ» ÀûÀýÇÏ°Ô °ËÁõÇÏÁö ¸øÇÏ´Â ¹®Á¦¿¡¼­ ±âÀÎÇÑ´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸µéÀ» ÈÉÃij»°í ´Ù¸¥ °ø°ÝµéÀ» µ¿¿øÇÑ À¯ÀÎ(Phishing) °ø°ÝµéÀ» À¯µµÇÒ ¼ö ÀÖ´Ù. À̰ÍÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ 'location' °´Ã¼ ³»ÀÇ ¸Þ½îµåµéÀ» µ¤¾î¾µ ¼ö ÀÖ´Â Àß Á¶ÀÛµÈ URLÀ» ¸¸µé¾î ºê¶ó¿ìÀú¿Í ¼­¹ö°£ÀÇ ½Å·Ú °ü°è¸¦ °¡Áö°í Èñ»ýÀÚÀÇ ºê¶ó¿ìÀúÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0131.html
http://www.osvdb.org/8331
http://www.secunia.com/advisories/12233
http://www.secunia.com/advisories/12235
http://www.greymagic.com/security/advisories/gm008-op/
http://security.gentoo.org/glsa/glsa-200408-05.xml

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Opera Software, Opera 7.53 ÀÌÇÏ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Opera À¥ »çÀÌÆ®¿¡¼­ OperaÀÇ °¡Àå ÃֽйöÀü (7.54 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.opera.com/download/
°ü·Ã URL (CVE)
°ü·Ã URL 10873 (SecurityFocus)
°ü·Ã URL 16904 (ISS)