English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21881
À§Çèµµ 40
Æ÷Æ® 80,6080, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â 4.3 ÀÌÀüÀÇ Winmail ServerÀÇ ¾î¶² ¹öÀüÀ» °¡µ¿ ÁßÀÌ´Ù. Winmail ¼­¹ö´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ È®À强ÀÖ´Â º¸¾È ±â´ÉµéÀ» °®Ãá »ó¿ë ¸ÞÀÏ ¼­¹öÀÌ´Ù. Winmail ¼­¹ö ¹öÀü 4.2 (build 0824)¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site Scripting ¹× ½ºÅ©¸³Æ® °ø°ÝµéÀ» ¼öÇàÇϰųª ÀÓÀÇÀÇ ÆÄÀϵéÀ» µ¤¾î¾²´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ Winmail ServerÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/16665
http://secunia.com/secunia_research/2005-58/advisory/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
AMAX Information Technologies »ç, Winmail ¼­¹ö ¹öÀü 4.2 (build 0824)¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Winmail Server ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.magicwinmail.net/download.asp ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Winmail ServerÀÇ °¡Àå ÃֽŠ¹öÀü(4.3(Build 0302))À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-1250 (CVE)
°ü·Ã URL 17009 (SecurityFocus)
°ü·Ã URL 23132,23140 (ISS)