Ãë¾àÁ¡ID |
210032 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WordPress ÇÁ·Î±×·¥Àº mbstring È®Àå¿¡ ÀÖ´Â SQL ÁÖÀÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. WordPress 2.0.6 ÀÌÀüÀÇ ¹öÀüµéÀº ´Ù¸¥ ¹®ÀÚ¼¼Æ® Trackbackµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ SQL ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à PHPÀÇ mbstring È®ÀåÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¾î¶² ¶Ç´Ù¸¥(alternate) ¹®ÀÚ¼¼Æ®¸¦ ¸í±âÇÏ¿© TrackbackÀ» ÀÇ·ÚÇÒ ¶§ ±× ¹®ÀÚ¼¼Æ®¸¦ °¡Áö°í ÀÔ·ÂÀ» ÀÎÄÚµùÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â SQL ÁÖÀÔ º¸È£ ±â¹ýµéÀ» ¿ìȸÇÒ ¼ö ÀÖÀ¸¸ç ÀÓÀÇÀÇ SQL ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://wordpress.org/development/2007/01/wordpress-206/ http://www.hardened-php.net/advisory_022007.141.html http://www.securityfocus.com/archive/1/archive/1/456049/100/0/threaded http://secunia.com/advisories/23595 http://secunia.com/advisories/23741
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Matthew Mullenweg, WordPress 2.0.6 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
OpenPKGÀÇ °æ¿ì: ´ÙÀ½ OpenPKG º¸¾È ±Ç°í¾È OpenPKG-SA-2007.005¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ OpenPKG cacti ÆÐÅ°Áö¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html
±âŸ Ç÷§ÆûÀÇ °æ¿ì: WordPress À¥ »çÀÌÆ®ÀÎ http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WordPressÀÇ °¡Àå ÃֽŠ¹öÀü(2.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2007-0107 (CVE) |
°ü·Ã URL |
21896,21907 (SecurityFocus) |
°ü·Ã URL |
31297 (ISS) |
|