Ãë¾àÁ¡ID |
21578 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
SympaÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â queue.c¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Sympa´Â ¸®´ª½º Ç÷§ÆûµéÀ» À§ÇÑ °ø°³ ¼Ò½º ¸ÞÀϸµ ¸®½ºÆ® ÇÁ·Î±×·¥ÀÌ´Ù. Sympa 4.1.2 ÀÌÇÏÀÇ ¹öÀüµéÀº ½ºÅÃ(stack) ±â¹ÝÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº ·ÎÄà °ø°ÝÀڵ鿡 ÀÇÇØ »óÀ§ ±ÇÇÑÀ» ȹµæÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¸í·É¾î ¶óÀÎ ÀμöµéÀ» ó¸®ÇÒ ¶§ Å¥(queue) À¯Æ¿¸®Æ¼ÀÇ ¹öÆÛ ±æÀÌ °Ë»ç ¿À·ù·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹ö »ó¿¡ ¼³Ä¡µÈ Sympa ¼ÒÇÁÆ®¿þ¾îÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sympa, Sympa 4.1.2 ÀÌÇÏÀÇ ¹öÀüµé Linux Any version |
ÇØ°áÃ¥ |
SympaÀÇ À¥ »çÀÌÆ®ÀÎ http://www.sympa.org ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â SympaÀÇ °¡Àå ÃֽŠ¹öÀü(4.1.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-677-1À» ÂüÁ¶ÇÏ¿© sympaÀÇ °¡Àå ÃֽŠ¹öÀü(3.3.3-3woody2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2005/dsa-677 |
°ü·Ã URL |
CVE-2005-0073 (CVE) |
°ü·Ã URL |
12527 (SecurityFocus) |
°ü·Ã URL |
19307 (ISS) |
|