English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28649
À§Çèµµ 20
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç Mozilla/Firefox ¹öÀü¿¡ µû¸£¸é ÇØ´ç ¹öÀü¿¡´Â Null ¹®ÀÚ¸¦ ÅëÇÑ MIME Çü½Ä ½ºÇªÇÎ(spoofing) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Mozilla/Firefox ´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ ¿ÀÇ ¼Ò½º À¥ ºê¶ó¿ìÀúÀÌ´Ù. ÀϺΠMozilla/Firefox ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÆÄÀÏÀÇ MIME Çü½ÄÀ» º¯Á¶Çϵµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ ÆÄÀÏÀ» ¿­±â Àü¿¡ ÀԷ¿¡ ´ëÇÑ ÀûÀýÇÑ °Ë»ç¸¦ ¼öÇàÇÏÁö ¸øÇϱ⠶§¹®ÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÆÄÀÏ¸í µÚ¿¡ ³Î(NULL) ¹®ÀÚ¸¦ µ¡ºÙÀÎ ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, MIME Çü½ÄÀ» º¯Á¶ÇÏ°í °¡´ÉÇÏ´Ù¸é ½Ã½ºÅÛ¿¡¼­ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼öµµ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/8307
http://archives.neohapsis.com/archives/bugtraq/2004-07/0119.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mozilla Firefox 0.9.1 °ú ±× ÀÌÀü ¹öÀüµé
Conectiva Linux 10, 9.0
Red Hat Advanced Workstation 2.1, Red Hat Desktop 3
Red Hat Enterprise Linux 2.1AS, 2.1ES, 2.1WS, 3AS, 3ES, 3WS
Slackware Linux 10.0, 9.1, current
SuSE Linux 8.1, 8.2, 9.0, 9.1
SuSE Linux Desktop 1.0
SuSE Linux Enterprise Server 8, 9
Microsoft Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ Mozilla ÇÁ·ÎÁ§Æ® À¥ »çÀÌÆ® http://www.mozilla.org/ ·ÎºÎÅÍ ÇØ´ç Ãë¾àÁ¡ÀÌ ÇØ°áµÈ Firefox ¹öÀü(0.9.3°ú ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Reg Hat º¸¾È ±Ç°í¹® RHSA-2004:421-17¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-421.html


SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È °ø°í¹® SUSE-SA:2004:036¸¦ ÂüÁ¶ÇÏ¿© ÃÖ½ÅÀÇ Mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_36_mozilla.html

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0760 (CVE)
°ü·Ã URL 10709 (SecurityFocus)
°ü·Ã URL 16691 (ISS)