Ãë¾àÁ¡ID |
21675 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüÀÌ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³´Ù. Cacti´Â PHP·Î Á¦ÀÛµÈ ³×Æ®¿öÅ© ±×·¡ÇÈ ÀÛ¾÷À» À§ÇÑ RRDTool(Round Robin Database tool)·ÎÀÇ À¥ ±â¹ÝÀÇ ÀüÀ§ 󸮱âÀÌ´Ù. CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:
1) "no_http_headers" Àμö·Î °Ç³×Áø ÀÔ·ÂÀº »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô °ËÁõµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ¼¼¼Ç ±¸Á¶Ã¼µéÀ» ÀçÀÛ¼ºÇÏ¿© ¾î¶² ÇÊÅ͸µ ¸ÞÄ¿´ÏÁòµéÀ» ¿ìȸÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¼º°øÀûÀÎ µµ¿ëÀº °ü¸®ÀÚ ±ÇÇÑÀ» ¾ò°Å³ª ´Ù¾çÇÑ SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ±×·¯³ª ¹Ýµå½Ã "register_globals"ÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. 2) °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ ÀÖ´Â ¿¡·¯´Â "rrdtool"·ÎÀÇ °æ·Î¸¦ Á¶ÀÛÇÔÀ¸·Î½á ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» ÁÖÀÔÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.hardened-php.net/advisory-032005.php http://www.hardened-php.net/advisory-042005.php http://www.hardened-php.net/advisory-052005.php http://secunia.com/advisories/15908/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüµé Linux Any version Unix Any version |
ÇØ°áÃ¥ |
Cacti ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.cacti.net/download_cacti.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â CactiÀÇ °¡Àå ÃֽŠ¹öÀü(0.8.6f ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-2149 (CVE) |
°ü·Ã URL |
14128,14129,14130 (SecurityFocus) |
°ü·Ã URL |
21241,21242 (ISS) |
|