| Ãë¾àÁ¡ID |
21214 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
À¥¼¹ö¿¡ "mmstdod.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. MailManÀº Endymion»çÀÇ Á¦Ç°À¸·Î POP3¿Í SMTP¸¦ °æÀ¯ÇÏ¿© emailÀ» ó¸®ÇÏ´Â À¥±â¹ÝÀÇ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇÑ´Ù. MailManÀº ¼³Ä¡¿Í Á¶ÀÛÀÌ ¸Å¿ì ½±±â ¶§¹®¿¡ ¸¹ÀÌ »ç¿ëµÈ´Ù. ±×·¯³ª MailMan Webmail ¹öÀü 3.0.26 ¹Ì¸¸ÀÇ ¸ðµç 3.x ¹öÀüµéÀÇ "mmstdod.cgi" CGI¿¡´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Äڵ忡´Â »ç¿ëÀÚÀÇ ºÒ¼øÇÑ ¸ñÀûÀÇ µ¥ÀÌŸ¸¦ °É·¯³»Áö ¾Ê´Â º¸¾È¿¡ Ãë¾àÇÑ open() È£ÃâµéÀÌ Á¸ÀçÇÑ´Ù. ±× È£ÃâµéÀº ¿ø°ÝÀ¸·Î http µ¥¸óÀÇ ±ÇÇÑ(root ȤÀº nobody)À¸·Î ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇàÇϴµ¥ »ç¿ëµÈ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/2063 http://www.iss.net/security_center/static/5649.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¿¡¼ MailMan (3.0.26)ÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. http://endymion.com/ |
| °ü·Ã URL |
CVE-2001-0021 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|