Ãë¾àÁ¡ID |
210028 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Cacti ÇÁ·Î±×·¥Àº cmd.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ ÀÓÀÇÀÇ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Cacti´Â PHP·Î Á¦ÀÛµÈ ³×Æ®¿öÅ© ±×·¡ÇÈ ÀÛ¾÷À» À§ÇÑ RRDTool(Round Robin Database tool)·ÎÀÇ À¥ ±â¹ÝÀÇ ÀüÀ§ 󸮱âÀÌ´Ù. Cacti 0.8.6i ÀÌÇÏÀÇ ¹öÀüµéÀº cmd.php ½ºÅ©¸³Æ®·ÎÀÇ µÎ¹ø° ȤÀº ¼¼¹ø° ÀμöµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ SQL ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_argc_argv ¿É¼ÇÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, cmd.php ½ºÅ©¸³Æ®·ÎÀÇ Àß Á¶ÀÛµÈ SQL ¹®ÀåµéÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ SQL ÁÖÀÔ °ø°ÝµéÀ» ½ÇÇàÇϰųª ½ÉÁö¾î À¥ ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://forums.cacti.net/about18846.html http://bugs.cacti.net/view.php?id=883 http://securitytracker.com/id?1017451 http://secunia.com/advisories/23528
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: The Cacti Group, CactiÀÇ 0.8.6i ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
OpenPKGÀÇ °æ¿ì: ´ÙÀ½ OpenPKG º¸¾È ±Ç°í¾È OpenPKG-SA-2007.001À» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ OpenPKG cacti ÆÐÅ°Áö¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html
SUSE LinuxÀÇ °æ¿ì: http://www.suse.com/support/security/advisories/2007_07_cacti.html
Gentoo LinuxÀÇ °æ¿ì: http://www.gentoo.org/security/en/glsa/glsa-200701-23.xml
DebianÀÇ °æ¿ì: http://www.debian.org/security/2007/dsa-1250
±âŸ Ç÷§ÆûÀÇ °æ¿ì: Cacti ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.cacti.net/download_cacti.php ¿¡¼ 0.8.6j º¸´Ù ´õ »óÀ§ÀÇ CactiÀÇ ¾î¶² ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-6799 (CVE) |
°ü·Ã URL |
21799 (SecurityFocus) |
°ü·Ã URL |
31177 (ISS) |
|