| Ãë¾àÁ¡ID |
21095 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
Hughes Technology »ç¿¡ ÀÇÇØ °³¹ßµÈ w3-msql CGI ½ºÅ©¸³Æ®´Â Mini-SQL¿¡ °°ÀÌ Æ÷ÇÔµÇ¾î ³ª¿À¸ç CGI ÇÁ·Î±×·¥À¸·Î msqlÀ» À§ÇÑ À¥ ÀÎÅÍÆäÀ̽º·Î µ¿ÀÛÇÑ´Ù. ±×·¯³ª ÀÌ CGI¿¡´Â Buffer Overflow Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â content-length Çʵ忡 ¾²ÀÌ´Â ¹öÆÛ¿¡ ±âÀÎÇÏ´Â ¹®Á¦·Î scanf() È£Ãâ½Ã Overflow°¡ ¹ß»ýÇÑ´Ù. À̸¦ ÀÌ¿ëÇÏ¸é ¿ø°ÝÀ¸·Î À¥¼¹öÀÇ uid·Î½á ¼¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Çϸé Buffer Overflow¸¦ Å×½ºÆ®ÇÒ ¼ö ÀÖ´Ù.
GET /cgi-bin/w3-msql/AAAA...AAAA HTTP/1.0
* Âü°í »çÀÌÆ®: http://www.tryc.on.ca/archives/bugtraq/1999_3/1074.html http://www.securityfocus.com/bid/898
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
Àӽ÷Π/cgi-bin µð·ºÅ丮¿¡ w3-msql¸¦ Á¦°ÅÇØ ³õ¾Æ¾ß ÇÑ´Ù. ±×¸®°íMini-sqlÀÇ Á¦ÀÛ»ç (http://www.hughes.com.au/products/msql/)¿¡¼ ÃֽŠPatch¸¦ ¹Þ¾Æ ¼³Ä¡Çϰųª ÃֽйöÀüÀÇ Mini-sql·Î ¾÷±×·¹À̵å ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0012 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|