Ãë¾àÁ¡ID |
28649 |
À§Çèµµ |
20 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç Mozilla/Firefox ¹öÀü¿¡ µû¸£¸é ÇØ´ç ¹öÀü¿¡´Â Null ¹®ÀÚ¸¦ ÅëÇÑ MIME Çü½Ä ½ºÇªÇÎ(spoofing) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Mozilla/Firefox ´Â Mozilla ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ °³¹ßµÈ ¿ÀÇ ¼Ò½º À¥ ºê¶ó¿ìÀúÀÌ´Ù. ÀϺΠMozilla/Firefox ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÆÄÀÏÀÇ MIME Çü½ÄÀ» º¯Á¶Çϵµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ ÆÄÀÏÀ» ¿±â Àü¿¡ ÀԷ¿¡ ´ëÇÑ ÀûÀýÇÑ °Ë»ç¸¦ ¼öÇàÇÏÁö ¸øÇϱ⠶§¹®ÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÆÄÀÏ¸í µÚ¿¡ ³Î(NULL) ¹®ÀÚ¸¦ µ¡ºÙÀÎ ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, MIME Çü½ÄÀ» º¯Á¶ÇÏ°í °¡´ÉÇÏ´Ù¸é ½Ã½ºÅÛ¿¡¼ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼öµµ ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.osvdb.org/8307 http://archives.neohapsis.com/archives/bugtraq/2004-07/0119.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Mozilla Firefox 0.9.1 °ú ±× ÀÌÀü ¹öÀüµé Conectiva Linux 10, 9.0 Red Hat Advanced Workstation 2.1, Red Hat Desktop 3 Red Hat Enterprise Linux 2.1AS, 2.1ES, 2.1WS, 3AS, 3ES, 3WS Slackware Linux 10.0, 9.1, current SuSE Linux 8.1, 8.2, 9.0, 9.1 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8, 9 Microsoft Windows ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Mozilla ÇÁ·ÎÁ§Æ® À¥ »çÀÌÆ® http://www.mozilla.org/ ·ÎºÎÅÍ ÇØ´ç Ãë¾àÁ¡ÀÌ ÇØ°áµÈ Firefox ¹öÀü(0.9.3°ú ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Reg Hat º¸¾È ±Ç°í¹® RHSA-2004:421-17¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2004-421.html
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE º¸¾È °ø°í¹® SUSE-SA:2004:036¸¦ ÂüÁ¶ÇÏ¿© ÃÖ½ÅÀÇ Mozilla ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_36_mozilla.html
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2004-0760 (CVE) |
°ü·Ã URL |
10709 (SecurityFocus) |
°ü·Ã URL |
16691 (ISS) |
|