English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21842
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â ¹öÀü 1.4.6 ÀÌÀüÀÇ SquirrelMail ÇÁ·Î±×·¥ÀÇ ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î ³ªÅ¸³­´Ù. SquirrelMailÀº PHP4·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ¸ÞÀÏ ½Ã½ºÅÛÀÌ´Ù. SquirrelMail 1.4.6 ÀÌÀüÀÇ ¹öÀüµéÀº
´ÙÁßÀÇ Cross-Site Scripting°ú IMAP ÁÖÀÔ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀÔ·ÂÀ» ÀûÀýÇÏ°Ô °É·¯ ³»Áö ¸øÇÏ´Â µ¥ ¿øÀÎÀÌ ÀÖ´Ù. °ø°ÝÀÚ´Â Cross-Site Scripting Ãë¾àÁ¡µéÀ» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼­ ÀǽÉÀÌ ¾ø´Â »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú¿¡¼­ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® Äڵ尡 ½ÇÇàµÇµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ÄíÅ° ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª ´Ù¸¥ °ø°ÝµéÀÇ ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. SquirrelMail 1.4.0¿¡¼­ 1.4.5 ±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â CRLF ÁÖÀÔ Ãë¾àÁ¡(ȤÀº "IMAP ÁÖÀÔ Ãë¾àÁ¡")Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ sqimap_mailbox_select ¸í·ÉÀÇ mailbox Àμö¿¡ ÀÖ´Â ½Å±Ô¶óÀÎ ¹®ÀÚµéÀ» ÅëÇØ ÀÓÀÇÀÇ IMAP ¸í·ÉµéÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ SquirrelMail ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.squirrelmail.org/security/issue/2006-02-01
http://www.squirrelmail.org/security/issue/2006-02-10
http://www.squirrelmail.org/security/issue/2006-02-15
http://archives.neohapsis.com/archives/bugtraq/2006-02/0513.html
http://secunia.com/advisories/18985/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SquirrelMail Project Team, SquirrelMail (1.4.6-RC1À» Æ÷ÇÔÇÑ) 1.4.6 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀüµé
ÇØ°áÃ¥ SquirrelMailÀÇ ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.squirrelmail.org/download.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SquirrelMailÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-0188,CVE-2006-0195,CVE-2006-0377 (CVE)
°ü·Ã URL 16756 (SecurityFocus)
°ü·Ã URL 24847,24848,24849 (ISS)