English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21214
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í À¥¼­¹ö¿¡ "mmstdod.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. MailManÀº Endymion»çÀÇ Á¦Ç°À¸·Î POP3¿Í SMTP¸¦ °æÀ¯ÇÏ¿© emailÀ» ó¸®ÇÏ´Â À¥±â¹ÝÀÇ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇÑ´Ù. MailManÀº ¼³Ä¡¿Í Á¶ÀÛÀÌ ¸Å¿ì ½±±â ¶§¹®¿¡ ¸¹ÀÌ »ç¿ëµÈ´Ù.
±×·¯³ª MailMan Webmail ¹öÀü 3.0.26 ¹Ì¸¸ÀÇ ¸ðµç 3.x ¹öÀüµéÀÇ "mmstdod.cgi" CGI¿¡´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Äڵ忡´Â »ç¿ëÀÚÀÇ ºÒ¼øÇÑ ¸ñÀûÀÇ µ¥ÀÌŸ¸¦ °É·¯³»Áö ¾Ê´Â º¸¾È¿¡ Ãë¾àÇÑ open() È£ÃâµéÀÌ Á¸ÀçÇÑ´Ù. ±× È£ÃâµéÀº ¿ø°ÝÀ¸·Î http µ¥¸óÀÇ ±ÇÇÑ(root ȤÀº nobody)À¸·Î ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇàÇϴµ¥ »ç¿ëµÈ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2063
http://www.iss.net/security_center/static/5649.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¿¡¼­ MailMan (3.0.26)ÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://endymion.com/
°ü·Ã URL CVE-2001-0021 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)