Ãë¾àÁ¡ID |
210175 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
¿ø°Ý À¥ ¼¹ö¿¡ phpMyAdmin 4.8.5 ÀÌÀü 4.0.x ¹öÀüÀÌ °¡µ¿ ÁßÀÔ´Ï´Ù. ÇØ´ç ¹öÀüÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. - AllowArbitraryServer ¼³Á¤À» true·Î ¼³Á¤ÇÏ¸é °¡Â¥ MySQL ¼¹ö¸¦ »ç¿ëÇÏ¿© °ø°ÝÀÚ´Â À¥ ¼¹ö »ç¿ëÀÚ°¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ´Â ¼¹ö»óÀÇ ¸ðµç ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù. phpMyadminÀº LOAD DATA INFILEÀÇ »ç¿ëÀ» Â÷´ÜÇÏ·Á°í ½ÃµµÇÏÁö¸¸ ¹ö±×·Î ÀÎÇØ PHP¿¡¼ ÀÌ Ã¼Å©´Â ¹Þ¾Æ µé¿©ÁöÁö ¾Ê½À´Ï´Ù. ¶ÇÇÑ 'MySQL'È®ÀåÀÚ¸¦ »ç¿ëÇÏ¸é ±âº»ÀûÀ¸·Î mysql.allow_local_infileÀÌ È°¼ºÈµË´Ï´Ù. ÀÌ µÎ Á¶°Ç ¸ðµÎ °ø°ÝÀ» Çã¿ëÇÕ´Ï´Ù. (CVE-2019-6799) - Ưº°È÷ Á¦ÀÛ µÈ »ç¿ëÀÚ À̸§À» »ç¿ëÇÏ¿© µðÀÚÀÌ³Ê ±â´ÉÀ» ÅëÇØ SQL ÁÖÀÔ °ø°ÝÀ» Æ®¸®°Å ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. (CVE-2019-6798)
* Âü°í »çÀÌÆ®: https://www.phpmyadmin.net/security/PMASA-2019-1/ https://www.phpmyadmin.net/security/PMASA-2019-2/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpMyAdmin 4.8.5 ¹öÀü ÀÌÀüÀÇ 4.x ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ phpMyAdmin ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â phpMyAdminÀÇ °¡Àå ÃֽŠ¹öÀü(4.8.5 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.phpmyadmin.net/home_page/downloads.php |
°ü·Ã URL |
CVE-2019-6798,CVE-2019-6799 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|