Ãë¾àÁ¡ID |
21842 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â ¹öÀü 1.4.6 ÀÌÀüÀÇ SquirrelMail ÇÁ·Î±×·¥ÀÇ ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î ³ªÅ¸³´Ù. SquirrelMailÀº PHP4·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ¸ÞÀÏ ½Ã½ºÅÛÀÌ´Ù. SquirrelMail 1.4.6 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Cross-Site Scripting°ú IMAP ÁÖÀÔ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀÔ·ÂÀ» ÀûÀýÇÏ°Ô °É·¯ ³»Áö ¸øÇÏ´Â µ¥ ¿øÀÎÀÌ ÀÖ´Ù. °ø°ÝÀÚ´Â Cross-Site Scripting Ãë¾àÁ¡µéÀ» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼ ÀǽÉÀÌ ¾ø´Â »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú¿¡¼ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® Äڵ尡 ½ÇÇàµÇµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ÄíÅ° ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª ´Ù¸¥ °ø°ÝµéÀÇ ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. SquirrelMail 1.4.0¿¡¼ 1.4.5 ±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â CRLF ÁÖÀÔ Ãë¾àÁ¡(ȤÀº "IMAP ÁÖÀÔ Ãë¾àÁ¡")Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ sqimap_mailbox_select ¸í·ÉÀÇ mailbox Àμö¿¡ ÀÖ´Â ½Å±Ô¶óÀÎ ¹®ÀÚµéÀ» ÅëÇØ ÀÓÀÇÀÇ IMAP ¸í·ÉµéÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹ö »ó¿¡ ¼³Ä¡µÈ SquirrelMail ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.squirrelmail.org/security/issue/2006-02-01 http://www.squirrelmail.org/security/issue/2006-02-10 http://www.squirrelmail.org/security/issue/2006-02-15 http://archives.neohapsis.com/archives/bugtraq/2006-02/0513.html http://secunia.com/advisories/18985/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SquirrelMail Project Team, SquirrelMail (1.4.6-RC1À» Æ÷ÇÔÇÑ) 1.4.6 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀüµé |
ÇØ°áÃ¥ |
SquirrelMailÀÇ ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.squirrelmail.org/download.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â SquirrelMailÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-0188,CVE-2006-0195,CVE-2006-0377 (CVE) |
°ü·Ã URL |
16756 (SecurityFocus) |
°ü·Ã URL |
24847,24848,24849 (ISS) |
|