Ãë¾àÁ¡ID |
21808 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PerlDesk ÇÁ·Î±×·¥Àº pdesk.cgi ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÆÄÀÏ Æ÷ÇÔ(inclusion) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. PerlDesk´Â Perl·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ¾È³»µ¥½ºÅ©(help desk) ÀÌÀÚ email °ü¸® ÇÁ·Î±×·¥ÀÌ´Ù. PerlDesk ¹öÀü 1.8°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº pdesk.cgi ½ºÅ©¸³Æ®ÀÇ lang Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼¹ö »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(../)°ú null ¹ÙÀÌÆ®(%00)¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³»°Å³ª ÀÓÀÇÀÇ Perl ¸ðµâµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=109509026406554&w=2 http://archives.neohapsis.com/archives/bugtraq/2004-09/0109.html http://www.osvdb.org/9954 http://secunia.com/advisories/12512
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: LogicNow, PerlDesk ¹öÀü 1.8°ú ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
PerlDesk´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-1677,CVE-2004-1678 (CVE) |
°ü·Ã URL |
11160 (SecurityFocus) |
°ü·Ã URL |
17343,19712 (ISS) |
|