English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210064
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç GForge ¼ÒÇÁÆ®¿þ¾î´Â 'cvsweb.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. GForge´Â À¥ ±â¹ÝÀÇ Çù¾÷ °³¹ß ȯ°æÀÌ´Ù. GForge 4.5.16 ÀÌÇÏÀÇ ¹öÀüµéÀº 'plugins/scmcvs/cvsweb.php' ½ºÅ©¸³Æ®·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. PATH_INFO Àμö¸¦ ÀÌ¿ëÇÏ¿© cvsweb.php ½ºÅ©¸³Æ®·Î Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» »ðÀÔÇÏ°í ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/25395

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Gforge Group, Gforge 4.5.16 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ GForge À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ÃֽŹöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Https://gforgegroup.com/downloads

Debian GNU/LinuxÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-1239-1À» ÂüÁ¶ÇÏ¿© sql-ledger ÆÐÅ°ÁöÀÇ ±³Á¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.us.debian.org/security/2006/dsa-1239
°ü·Ã URL CVE-2007-0246 (CVE)
°ü·Ã URL 24141 (SecurityFocus)
°ü·Ã URL 34510 (ISS)