| Ãë¾àÁ¡ID |
21072 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ 'php.cgi' cgi°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. php CGI ÇÁ·Î±×·¥(php.cgi)Àº PHP/FI ÆÐŰÁöÀÇ ÀϺηΠRasmus Lerdorf¿¡ ÀÇÇØ ¸¸µé¾î Á³´Ù. ÇöÀç±îÁö ÀÌ ÇÁ·Î±×·¥¿¡´Â µÎ°³ÀÇ Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú´Ù.
1. ¿ÜºÎ »ç¿ëÀÚ°¡ ÀÌ CGI¸¦ ÀÌ¿ëÇÏ¿© À¥¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î Àо ¼ö ÀÖ´Ù.
2. ÀÌ ÇÁ·Î±×·¥Àº ¿ÜºÎ »ç¿ëÀÚ¿¡ ÀÇÇØ À¥¼¹ö »óÀÇ ÀÓÀÇÀÇ ¸í·ÉÀÌ ¼öÇàµÉ ¼ö ÀÖ´Â Buffer Overflow Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¹°·Ð ±× ¸í·ÉµéÀº httpd ÇÁ·Î¼¼½ºÀÇ ±ÇÇÑ, ´ë°³´Â nobody·Î ¼öÇàµÈ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é Áï½Ã php.cgi¸¦ Á¦°ÅÇϰųª ½ÇÇà ÆÛ¹Ì¼ÇÀ» ¾ø¾Ö¾ß ÇÑ´Ù. PHP/FIÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Ãë¾àÇÑ ½Ã½ºÅÛ ~~~~~~~~~~ ¾î¶² ¿î¿µÃ¼Á¦¿¡¼µç php.cgi 2.0beta10 ÀÌÇÏÀÇ ¹öÀüÀ» »ç¿ëÇÏ´Â ¸ðµç ½Ã½ºÅÛµéÀº Ãë¾àÇÏ´Ù. ´Ù¸¸ Apache ¸ðµâ·Î½á ÄÄÆÄÀÏ Çß´Ù¸é PHP¿¡´Â ±×·¯ÇÑ ¹®Á¦°¡ ¹ß»ýÇÏÁö ¾Ê´Â´Ù. À¥¼¹ö¿¡ php.cgi°¡ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö¸¦ È®ÀÎÇØ º¸±â À§Çؼ´Â À¥ºê¶ó¿ìÁî¿¡¼ ´ÙÀ½°ú °°ÀÌ URLÀ» ÁÖ¾î¼ È®ÀÎÇÒ ¼ö ÀÖ´Ù.
http://hostname/cgi-bin/php.cgi
¸¸¾à ´ÙÀ½°ú °°ÀÌ ¹öÀüÀÌ ³ªÅ¸³´Ù¸é
PHP/FI Version 2.0b10 ...
PHP/FIÀÌ ¼öÇàµÇ°í ÀÖÀ½À» ÀǹÌÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0058 (CVE) |
| °ü·Ã URL |
712 (SecurityFocus) |
| °ü·Ã URL |
293 (ISS) |
|