English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210028
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Cacti ÇÁ·Î±×·¥Àº cmd.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ ÀÓÀÇÀÇ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Cacti´Â PHP·Î Á¦ÀÛµÈ ³×Æ®¿öÅ© ±×·¡ÇÈ ÀÛ¾÷À» À§ÇÑ RRDTool(Round Robin Database tool)·ÎÀÇ À¥ ±â¹ÝÀÇ ÀüÀ§ 󸮱âÀÌ´Ù. Cacti 0.8.6i ÀÌÇÏÀÇ ¹öÀüµéÀº cmd.php ½ºÅ©¸³Æ®·ÎÀÇ µÎ¹ø° ȤÀº ¼¼¹ø° ÀμöµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ SQL ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_argc_argv ¿É¼ÇÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, cmd.php ½ºÅ©¸³Æ®·ÎÀÇ Àß Á¶ÀÛµÈ SQL ¹®ÀåµéÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ SQL ÁÖÀÔ °ø°ÝµéÀ» ½ÇÇàÇϰųª ½ÉÁö¾î À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://forums.cacti.net/about18846.html
http://bugs.cacti.net/view.php?id=883
http://securitytracker.com/id?1017451
http://secunia.com/advisories/23528

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
The Cacti Group, CactiÀÇ 0.8.6i ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ OpenPKGÀÇ °æ¿ì:
´ÙÀ½ OpenPKG º¸¾È ±Ç°í¾È OpenPKG-SA-2007.001À» ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ OpenPKG cacti ÆÐÅ°Áö¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html

SUSE LinuxÀÇ °æ¿ì:
http://www.suse.com/support/security/advisories/2007_07_cacti.html

Gentoo LinuxÀÇ °æ¿ì:
http://www.gentoo.org/security/en/glsa/glsa-200701-23.xml

DebianÀÇ °æ¿ì:
http://www.debian.org/security/2007/dsa-1250

±âŸ Ç÷§ÆûÀÇ °æ¿ì:
Cacti ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.cacti.net/download_cacti.php ¿¡¼­ 0.8.6j º¸´Ù ´õ »óÀ§ÀÇ CactiÀÇ ¾î¶² ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-6799 (CVE)
°ü·Ã URL 21799 (SecurityFocus)
°ü·Ã URL 31177 (ISS)