English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21247
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ SquirrelMail ÆÐŰÁöÀÇ ¹öÀü¿¡ µû¸£¸é ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
SquirrelMailÀº PHP·Î Á¦ÀÛµÈ À¥ ¸ÞÀÏ ÆÐŰÁöÀÌ´Ù. SquirrelMail ¹öÀü 1.2.11 ÀÌÇϵ鿡´Â Á¤º¸ ³ëÃâ, µ¥ÀÌÅÍ ÆÄ±«, ±×¸®°í ±ÇÇÑ »ó½ÂÀ» Çã¿ëÇÒ ¼ö ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾ú´Ù. ¹®Á¦´Â HTTP ¿äûµé ³»¿¡ °Ç³×Áö´Â URI Àμöµé¿¡ ´ëÇÑ ºÒÃæºÐÇÑ ÇÊÅ͸µ 󸮷ΠÀÎÇØ ¹ß»ýÇÑ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ­´Â °ø°ÝÀÚ°¡ Ÿ´çÇÑ À¥ ¸ÞÀÏ °èÁ¤À» °¡Áö°í ÀÖ¾î¾ß ÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç SquirrelMailÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/326398
http://www.securityfocus.com/archive/1/326514

* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
SquirrelMail 1.2.11 ÀÌÇÏ
ÇØ°áÃ¥ SquirrelMail ÆÐŰÁöµéÀÇ °ø½Ä À¥ »çÀÌÆ®ÀÎ http://www.squirrelmail.org/ ·ÎºÎÅÍ SquirrelMailÀÇ °¡Àå ÃֽйöÀü (1.4.0 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 7952 (SecurityFocus)
°ü·Ã URL (ISS)