English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21034
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ "day5notifier.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ CGI´Â ¿ÜºÎ¿¡¼­ http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö»óÀÇ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØÁÖ´Â Àß ¾Ë·ÁÁø º¸¾ÈÃë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
handler ÇÁ·Î±×·¥Àº IRIXÀÇ Outbox Environment SubsystemÀÇ ºÎºÐÀ¸·Î¼­ IRIX 6.2 ÀÌ»óÀÇ ¸ðµç SGI ½Ã½ºÅÛ»ó¿¡ µðÆúÆ®·Î ¼³Ä¡µÈ´Ù. IRIXÀÇ ±¸ ¹öÀü¿¡¼­´Â ÀÌ ÆÐŰÁö°¡ ¿É¼ÇÀ¸·Î ¼³Ä¡µÆÀ» ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://bugacid.tripod.com/irix/httpd21.html
http://www.iss.net/security_center/static/3312.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ IRIX Outbox Environment Subsystem¿¡ ÀÖ´Â ÇØ´ç CGI¸¦ Disable ½ÃŲ´Ù. ±×¸®°í SGI¿¡¼­ Patch¸¦ ¹Þ¾Æ ¼³Ä¡ÇÑ´Ù.

scripts¸¦ Disable½Ã۱â À§Çؼ­´Â ´ÙÀ½ÀÇ ÀýÂ÷¸¦ µû¸¥´Ù.
# /bin/chmod 400 /var/www/cgi-bin/day5notifier.cgi
(/var/www°¡ µðÆúÆ® ÀνºÅç PathÀ϶§)
# /usr/sbin/versions -v remove outbox (outbox subsystem Á¦°Å)
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)