English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29108
À§Çèµµ 40
Æ÷Æ® 80
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í SonicWALL SOHO/10ÀÇ ÇØ´ç À¥ ÀÎÅÍÆäÀ̽º´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. SonicWALL SOHO/10Àº ¹æÈ­º®, VPN ÄÁÅÙÆ® ÇÊÅ͸µ µîÀ» Æ÷ÇÔÇÑ ¿©·¯ ¼³ºñµéÀ» °®Ãá ÀÎÅÍ³Ý º¸¾È ¾îÇöóÀ̾ð½º(Appliance)ÀÌ´Ù. SonicWALL SOHO/10 Æß¿þ¾î ¹öÀü 5.1.7.0Àº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Cross-Site Scripting ±×¸®°í ½ºÅ©¸³Æ® ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

1) SonicWALL SOHO/10¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡Àº Ãë¾àÇÑ »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼­ »ç¿ëÀÚ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) SonicWALL SOHO/10¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÄÚµå ÁÖÀÔ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ Äڵ带 Æ÷ÇÔÇÑ »ç¿ëÀÚ¸íÀ» ÀåºñÀÇ ·Î±×ÀÎ ÆäÀÌÁö·Î º¸³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ´Â Àåºñ°¡ »ç¿ëÀÚ¸íÀ» ·Î±×ÆÄÀÏ¿¡ ÀúÀåÇÏ°Ô ÇÏ´Â ¿øÀÎÀÌ µÈ´Ù. ±×¸®°í ³ª¼­ °ü¸®ÀÚ°¡ ±× ·Î±×ÆÄÀÏÀ» º¸·Á°í ÇÒ ¶§ ±× ¾ÇÀÇÀûÀÎ Äڵ尡 °ü¸®ÀÚÀÇ ºê¶ó¿ìÀú¿¡ ÀÇÇØ ½ÇÇàµÇ°Ô µÈ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2005/Apr/1013638.html
http://secunia.com/advisories/14823/
http://archives.neohapsis.com/archives/bugtraq/2005-04/0041.html
http://www.oliverkarow.de/research/sonicwall.txt

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SonicWALL SOHO/10 Æß¿þ¾î ¹öÀü 5.1.7.0
Microsoft Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
°ü·Ã URL CVE-2005-1006 (CVE)
°ü·Ã URL 12984 (SecurityFocus)
°ü·Ã URL 19958,19960 (ISS)