English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21808
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PerlDesk ÇÁ·Î±×·¥Àº pdesk.cgi ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÆÄÀÏ Æ÷ÇÔ(inclusion) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. PerlDesk´Â Perl·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ¾È³»µ¥½ºÅ©(help desk) ÀÌÀÚ email °ü¸® ÇÁ·Î±×·¥ÀÌ´Ù. PerlDesk ¹öÀü 1.8°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº pdesk.cgi ½ºÅ©¸³Æ®ÀÇ lang Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼­¹ö »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(../)°ú null ¹ÙÀÌÆ®(%00)¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³»°Å³ª ÀÓÀÇÀÇ Perl ¸ðµâµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=bugtraq&m=109509026406554&w=2
http://archives.neohapsis.com/archives/bugtraq/2004-09/0109.html
http://www.osvdb.org/9954
http://secunia.com/advisories/12512

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
LogicNow, PerlDesk ¹öÀü 1.8°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ PerlDesk´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2004-1677,CVE-2004-1678 (CVE)
°ü·Ã URL 11160 (SecurityFocus)
°ü·Ã URL 17343,19712 (ISS)