English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21095
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í Hughes Technology »ç¿¡ ÀÇÇØ °³¹ßµÈ w3-msql CGI ½ºÅ©¸³Æ®´Â Mini-SQL¿¡ °°ÀÌ Æ÷ÇÔµÇ¾î ³ª¿À¸ç CGI ÇÁ·Î±×·¥À¸·Î msqlÀ» À§ÇÑ À¥ ÀÎÅÍÆäÀ̽º·Î µ¿ÀÛÇÑ´Ù. ±×·¯³ª ÀÌ CGI¿¡´Â Buffer Overflow Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â content-length Çʵ忡 ¾²ÀÌ´Â ¹öÆÛ¿¡ ±âÀÎÇÏ´Â ¹®Á¦·Î scanf() È£Ãâ½Ã Overflow°¡ ¹ß»ýÇÑ´Ù. À̸¦ ÀÌ¿ëÇÏ¸é ¿ø°ÝÀ¸·Î À¥¼­¹öÀÇ uid·Î½á ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Çϸé Buffer Overflow¸¦ Å×½ºÆ®ÇÒ ¼ö ÀÖ´Ù.

GET /cgi-bin/w3-msql/AAAA...AAAA HTTP/1.0

* Âü°í »çÀÌÆ®:
http://www.tryc.on.ca/archives/bugtraq/1999_3/1074.html
http://www.securityfocus.com/bid/898

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ Àӽ÷Π/cgi-bin µð·ºÅ丮¿¡ w3-msql¸¦ Á¦°ÅÇØ ³õ¾Æ¾ß ÇÑ´Ù. ±×¸®°íMini-sqlÀÇ Á¦ÀÛ»ç (http://www.hughes.com.au/products/msql/)¿¡¼­ ÃֽŠPatch¸¦ ¹Þ¾Æ ¼³Ä¡Çϰųª ÃֽйöÀüÀÇ Mini-sql·Î ¾÷±×·¹À̵å ÇÑ´Ù.
°ü·Ã URL CVE-2000-0012 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)