English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21859
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PhpGedView ÇÁ·Î±×·¥Àº 3.3.7 ÀÌÇÏÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. PhpGedView´Â °¡°è ¶Ç´Â Ç÷Åë Á¤º¸¸¦ º¸¿© ÁÖ±â À§ÇØ ¹«·á·Î »ç¿ëÇÒ ¼ö ÀÖ´Â À¥ ±â¹ÝÀÇ ÇÁ·Î±×·¥ÀÌ´Ù. PhpGedView ¹öÀü 3.3.7°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) "help_text_vars.php" ½ºÅ©¸³Æ®¿¡ ÀÖ´Â "PGV_BASE_DIRECTORY" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº ÆÄÀϵéÀ» Include Çϱâ Àü¿¡ ÀûÀýÇÏ°Ô °ËÁõµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ¿ÜºÎ ¹× ³»ºÎ ÀÚ¿øµé·ÎºÎÅÍ ÀÓÀÇÀÇ ÆÄÀϵéÀ» Include ÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖÀ¸¸ç, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¸°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÏ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ­´Â "register_globals" ¼³Á¤ÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
2) "authenticate.php" ½ºÅ©¸³Æ®¿¡¼­ ÀúÀåµÇ¾î Áö±â Àü¿¡ µî·Ï ½Ã¿¡ "user_language", "user_email", ±×¸®°í "user_gedcomid" Àμöµé·Î Àü´ÞµÈ ÀÔ·ÂÀº ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ÀÓÀÇÀÇ PHP Äڵ带 ÁÖÀÔÇÏ°í ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://sourceforge.net/tracker/index.php?func=detail&aid=1386434&group_id=55456&atid=477081
http://archives.neohapsis.com/archives/bugtraq/2005-12/0243.html
http://secunia.com/advisories/18177/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
John Finlay, PhpGedView ¹öÀü 3.3.7°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ PhpGedViewÀÇ À¥ ÆäÀÌÁöÀÎ http://phpgedview.sourceforge.net/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PhpGedViewÀÇ °¡Àå ÃֽŠ¹öÀü(3.3.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-4467,CVE-2005-4468,CVE-2005-4469 (CVE)
°ü·Ã URL 15983 (SecurityFocus)
°ü·Ã URL 23871,23873 (ISS)