English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21877
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PHProjekt´Â ÀÎÁõÀ» ¿ä±¸ÇÏÁö ¾Ê°í 'setup.php' ÆÄÀÏ¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Çã¿ëÇÑ´Ù. PHProjekt´Â PHP4·Î Á¦ÀÛµÈ °ø°³ ¼Ò½º Groupware ÆÐÅ°ÁöÀÌ´Ù. PHProjekt ¹öÀü 4.2.1°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº 'setup.php' ÆÄÀÏ¿¡ ÀÖ´Â ¾Ë·ÁÁ® ÀÖÁö ¾ÊÀº ¿À·ù·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÎÁõ¾øÀÌ 'setup.php' ÆÄÀÏ¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Ç¥Àû À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ¿î¿µÃ¼Á¦ ½Ã½ºÅÛ ¸í·ÉµéÀ» Æ÷ÇÔÇÏ¿© ÀÓÀÇÀÇ PHP ½ºÅ©¸³Æ®µéÀ» ¾÷·ÎµåÇÏ°í ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.gentoo.org/security/en/glsa/glsa-200412-06.xml
http://www.securitytracker.com/alerts/2004/Dec/1012369.html
http://secunia.com/advisories/13355/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PHProjekt ¹öÀü 4.2.1°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ PHProjekt À¥ »çÀÌÆ®ÀÎ http://www.phprojekt.com/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PHProjektÀÇ °¡Àå ÃֽŠ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200412-06À» ÂüÁ¶ÇÏ¿© phprojektÀÇ °¡Àå ÃֽŠ¹öÀü(4.2-r1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200412-06.xml
°ü·Ã URL CVE-2004-2739 (CVE)
°ü·Ã URL 11797 (SecurityFocus)
°ü·Ã URL 18320 (ISS)