English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21099
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ "websendmail" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
Websendmail ÇÁ·Î±×·¥Àº ¿ÜºÎ¿¡¼­ http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. WebsendmailÀº WEBgais ÆÐŰÁö¿¡ µþ·ÁÀÖ´Â CGI ÇÁ·Î±×·¥ÀÌ´Ù. WEBgais´Â CGI gateway ÇÁ·Î±×·¥µéÀÇ ¸ðÀ½À¸·Î WWW information ¼­¹öµé¿¡¼­ °Ë»ö¿£ÁøÀ¸·Î »ç¿ëµÇ´Â Global Area Intelligent Search (GAIS)»çÀÇ index/query ½Ã½ºÅÛÀÌ´Ù. WebsendmailÀº ¾î¶² formÀ¸·ÎºÎÅÍ ¸ÞÀÏÀ» ÀÔ·Â¹Þ¾Æ ÁöÁ¤µÈ ¸ñÀûÁö·Î e-mailÀ» º¸³¾ ¼ö ÀÖ´Â ÇÁ·Î±×·¥À¸·Î v1.0b2 ±îÁöÀÇ WEBgais ¹öÀüµéÀÌ º¸¾È¿¡ Ãë¾àÇÏ´Ù.

¡Ø BUGTRAQ : Jul08,1997

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2077
http://xforce.iss.net/xforce/xfdb/296

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ /cgi-bin³» websendmail ÆÄÀÏÀ» Á¦°ÅÇϰųª ´ÙÀ½°ú °°ÀÌ ½ÇÇà½ÃŰÁö ¸øÇϵµ·Ï ÆÛ¹Ì¼ÇÀ» Á¶Á¤ÇÑ´Ù.

# /bin/chmod 400 /usr/local/etc/httpd/cgi-bin/websendmail
°ü·Ã URL CVE-1999-0196 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)