English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210046
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç LedgerSMB ȤÀº SQL-Ledger´Â admin.pl ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÀÎÁõ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. LedgerSMB ȤÀº SQL-Ledger´Â Perl·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ º¹½Ä ºÎ±â(double entry), ȸ°è ½Ã½ºÅÛÀÌ´Ù. SQL-Ledger 2.6.26 ÀÌÀüÀÇ ¹öÀüµé°ú LedgerSMB 1.1.9 ÀÌÀüÀÇ ¹öÀüµéÀº admin.pl ½ºÅ©¸³Æ®¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ ÀÎÁõÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ÀÎÁõÀ» ¿ìȸÇÏ°í °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://sourceforge.net/project/shownotes.php?release_id=492303&group_id=175965
http://archives.neohapsis.com/archives/bugtraq/2007-03/0086.html
http://secunia.com/advisories/24467/
http://secunia.com/advisories/24496/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
DWS Systems »ç, SQL-Ledger 2.6.26 ÀÌÀüÀÇ ¹öÀüµé
Open Source Technology Group, LedgerSMB 1.1.9 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SQL-LedgerÀÇ °æ¿ì:
SQL-Ledger À¥ »çÀÌÆ®ÀÎ http://www.sql-ledger.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃֽŠ¹öÀü(2.6.26 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

LedgerSMBÀÇ °æ¿ì:
SourceForge.net À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/ledger-smb/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃֽŠ¹öÀü(1.1.9 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2007-1436 (CVE)
°ü·Ã URL 22889 (SecurityFocus)
°ü·Ã URL 32954 (ISS)