English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210175
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ¿ø°Ý À¥ ¼­¹ö¿¡ phpMyAdmin 4.8.5 ÀÌÀü 4.0.x ¹öÀüÀÌ °¡µ¿ ÁßÀÔ´Ï´Ù. ÇØ´ç ¹öÀüÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
- AllowArbitraryServer ¼³Á¤À» true·Î ¼³Á¤ÇÏ¸é °¡Â¥ MySQL ¼­¹ö¸¦ »ç¿ëÇÏ¿© °ø°ÝÀÚ´Â À¥ ¼­¹ö »ç¿ëÀÚ°¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ´Â ¼­¹ö»óÀÇ ¸ðµç ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù. phpMyadminÀº LOAD DATA INFILEÀÇ »ç¿ëÀ» Â÷´ÜÇÏ·Á°í ½ÃµµÇÏÁö¸¸ ¹ö±×·Î ÀÎÇØ PHP¿¡¼­ ÀÌ Ã¼Å©´Â ¹Þ¾Æ µé¿©ÁöÁö ¾Ê½À´Ï´Ù. ¶ÇÇÑ 'MySQL'È®ÀåÀÚ¸¦ »ç¿ëÇÏ¸é ±âº»ÀûÀ¸·Î mysql.allow_local_infileÀÌ È°¼ºÈ­µË´Ï´Ù. ÀÌ µÎ Á¶°Ç ¸ðµÎ °ø°ÝÀ» Çã¿ëÇÕ´Ï´Ù. (CVE-2019-6799)
- Ưº°È÷ Á¦ÀÛ µÈ »ç¿ëÀÚ À̸§À» »ç¿ëÇÏ¿© µðÀÚÀÌ³Ê ±â´ÉÀ» ÅëÇØ SQL ÁÖÀÔ °ø°ÝÀ» Æ®¸®°Å ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. (CVE-2019-6798)

* Âü°í »çÀÌÆ®:
https://www.phpmyadmin.net/security/PMASA-2019-1/ https://www.phpmyadmin.net/security/PMASA-2019-2/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpMyAdmin 4.8.5 ¹öÀü ÀÌÀüÀÇ 4.x
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ phpMyAdmin ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â phpMyAdminÀÇ °¡Àå ÃֽŠ¹öÀü(4.8.5 ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.phpmyadmin.net/home_page/downloads.php
°ü·Ã URL CVE-2019-6798,CVE-2019-6799 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)