English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21660
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í SAP IGS°¡ ÇØ´ç È£½ºÆ®¿¡¼­ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î º¸ÀÌ¸ç µð·ºÅ丮 Ž»ö °ø°Ý¿¡ Ãë¾àÇÏ´Ù. SAP R3´Â ´Ù¾çÇÑ »ç¾÷ ±â´ÉµéÀ» ¼­ºñ½ºÇØ ÁÖ´Â ¿©·¯ °³ÀÇ ±¸¼º¿ä¼ÒµéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Â ÀαâÀÖ´Â ¾îÇø®ÄÉÀÌ¼Ç ÆÐÅ°ÁöÀÌ´Ù. IGS (Internet Graphics Server)´Â SAP R/3 ¿£ÅÍÇÁ¶óÀÌÁî ȯ°æÀÇ ºÎ°¡ÀûÀÎ ±¸¼º¿ä¼ÒÀÌ¸ç ¼Ò±Ô¸ðÀÇ À¥ ¼­¹ö·Î¼­ HTTP¸¦ ÅëÇØ ¾×¼¼½º °¡´ÉÇÏ´Ù. SAP R/3ÀÇ 6.40 Patch 11 ÀÌÀüÀÇ ¹öÀüµéÀº ¹®¼­ °æ·Î¸íµéÀ» ó¸®ÇÒ ¶§ SAPÀÇ Internet Graphics Server¿¡ ÀÖ´Â ÀÔ·Â °ËÁõ ¿À·ù·Î ÀÎÇÏ¿© µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. "dot dot" ½ÃÄö½º(/../)¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ ¹®¼­ °æ·Î¸¦ º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮ÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/16208/
http://online.securityfocus.com/archive/1/406375/30/0/threaded


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SAP R/3ÀÇ 6.40 Patch 11 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SAP R/3 À¥ »çÀÌÆ®ÀÎ http://service.sap.com/patches ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SAP IGS ¼ÒÇÁÆ®¿þ¾îÀÇ °¡Àå ÃֽŠ¹öÀü(6.40 Patch 11 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-1691 (CVE)
°ü·Ã URL 14369 (SecurityFocus)
°ü·Ã URL 21548 (ISS)