English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21675
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüÀÌ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Cacti´Â PHP·Î Á¦ÀÛµÈ ³×Æ®¿öÅ© ±×·¡ÇÈ ÀÛ¾÷À» À§ÇÑ RRDTool(Round Robin Database tool)·ÎÀÇ À¥ ±â¹ÝÀÇ ÀüÀ§ 󸮱âÀÌ´Ù. CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) "no_http_headers" Àμö·Î °Ç³×Áø ÀÔ·ÂÀº »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô °ËÁõµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ¼¼¼Ç ±¸Á¶Ã¼µéÀ» ÀçÀÛ¼ºÇÏ¿© ¾î¶² ÇÊÅ͸µ ¸ÞÄ¿´ÏÁòµéÀ» ¿ìȸÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¼º°øÀûÀÎ µµ¿ëÀº °ü¸®ÀÚ ±ÇÇÑÀ» ¾ò°Å³ª ´Ù¾çÇÑ SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ±×·¯³ª ¹Ýµå½Ã "register_globals"ÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
2) °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ ÀÖ´Â ¿¡·¯´Â "rrdtool"·ÎÀÇ °æ·Î¸¦ Á¶ÀÛÇÔÀ¸·Î½á ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» ÁÖÀÔÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.hardened-php.net/advisory-032005.php
http://www.hardened-php.net/advisory-042005.php
http://www.hardened-php.net/advisory-052005.php
http://secunia.com/advisories/15908/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CactiÀÇ 0.8.6f ÀÌÀü ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ Cacti ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.cacti.net/download_cacti.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â CactiÀÇ °¡Àå ÃֽŠ¹öÀü(0.8.6f ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2149 (CVE)
°ü·Ã URL 14128,14129,14130 (SecurityFocus)
°ü·Ã URL 21241,21242 (ISS)