Ãë¾àÁ¡ID |
21660 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
SAP IGS°¡ ÇØ´ç È£½ºÆ®¿¡¼ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î º¸ÀÌ¸ç µð·ºÅ丮 Ž»ö °ø°Ý¿¡ Ãë¾àÇÏ´Ù. SAP R3´Â ´Ù¾çÇÑ »ç¾÷ ±â´ÉµéÀ» ¼ºñ½ºÇØ ÁÖ´Â ¿©·¯ °³ÀÇ ±¸¼º¿ä¼ÒµéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Â ÀαâÀÖ´Â ¾îÇø®ÄÉÀÌ¼Ç ÆÐÅ°ÁöÀÌ´Ù. IGS (Internet Graphics Server)´Â SAP R/3 ¿£ÅÍÇÁ¶óÀÌÁî ȯ°æÀÇ ºÎ°¡ÀûÀÎ ±¸¼º¿ä¼ÒÀÌ¸ç ¼Ò±Ô¸ðÀÇ À¥ ¼¹ö·Î¼ HTTP¸¦ ÅëÇØ ¾×¼¼½º °¡´ÉÇÏ´Ù. SAP R/3ÀÇ 6.40 Patch 11 ÀÌÀüÀÇ ¹öÀüµéÀº ¹®¼ °æ·Î¸íµéÀ» ó¸®ÇÒ ¶§ SAPÀÇ Internet Graphics Server¿¡ ÀÖ´Â ÀÔ·Â °ËÁõ ¿À·ù·Î ÀÎÇÏ¿© µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. "dot dot" ½ÃÄö½º(/../)¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ ¹®¼ °æ·Î¸¦ º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮ÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/advisories/16208/ http://online.securityfocus.com/archive/1/406375/30/0/threaded
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SAP R/3ÀÇ 6.40 Patch 11 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
SAP R/3 À¥ »çÀÌÆ®ÀÎ http://service.sap.com/patches ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â SAP IGS ¼ÒÇÁÆ®¿þ¾îÀÇ °¡Àå ÃֽŠ¹öÀü(6.40 Patch 11 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-1691 (CVE) |
°ü·Ã URL |
14369 (SecurityFocus) |
°ü·Ã URL |
21548 (ISS) |
|