Ãë¾àÁ¡ID |
210064 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç GForge ¼ÒÇÁÆ®¿þ¾î´Â 'cvsweb.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. GForge´Â À¥ ±â¹ÝÀÇ Çù¾÷ °³¹ß ȯ°æÀÌ´Ù. GForge 4.5.16 ÀÌÇÏÀÇ ¹öÀüµéÀº 'plugins/scmcvs/cvsweb.php' ½ºÅ©¸³Æ®·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. PATH_INFO Àμö¸¦ ÀÌ¿ëÇÏ¿© cvsweb.php ½ºÅ©¸³Æ®·Î Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» »ðÀÔÇÏ°í ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/advisories/25395
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Gforge Group, Gforge 4.5.16 ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ GForge À¥ »çÀÌÆ®¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÃֽŹöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. Https://gforgegroup.com/downloads
Debian GNU/LinuxÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-1239-1À» ÂüÁ¶ÇÏ¿© sql-ledger ÆÐÅ°ÁöÀÇ ±³Á¤µÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.us.debian.org/security/2006/dsa-1239 |
°ü·Ã URL |
CVE-2007-0246 (CVE) |
°ü·Ã URL |
24141 (SecurityFocus) |
°ü·Ã URL |
34510 (ISS) |
|