English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21917
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 1.5.4b ÀÌÀüÀÇ Ideal BBÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Ideal BB´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ °Ô½ÃÆÇ ÇÁ·Î±×·¥ÀÌ´Ù. Ideal BB 1.5.4b ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ °áÇÔµéÀº ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ(Include), Á¤º¸ ³ëÃâ, Cross-Site Scripting, ±×¸®°í SQL ÁÖÀÔ Ãë¾àÁ¡µéÀ» Æ÷ÇÔÇÑ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» °ø°ÝÀÚ°¡ ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¾îÇø®ÄÉÀ̼ÇÀÇ Á¦¾î±Ç ȹµæ, µ¥ÀÌÅÍÀÇ ¾×¼¼½º ¹× ¼öÁ¤, ÄíÅ° ±â¹ÝÀÇ ÀÎÁõÁ¤º¸ Å»Ãë, À¥ ¼­¹ö ÇÁ·Î¼¼¼­ÀÇ ±ÇÇÑÀ¸·Î ¿ø°Ý PHP ÄÚµå ½ÇÇà, ¹Î°¨ÇÑ Á¤º¸ ȹµæÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù. ´Ù¸¥ Á¾·ùÀÇ °ø°Ýµé ¶ÇÇÑ °¡´ÉÇÏ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ Ideal BBÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2006-05/0136.html
http://www.securityfocus.com/archive/1/archive/1/433248/100
http://www.osvdb.org/25455
http://secunia.com/advisories/20035

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Ideal Science »ç, Ideal BB 1.5.4b ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Ideal BB´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2006-2317,CVE-2006-2318,CVE-2006-2319,CVE-2006-2320,CVE-2006-2321 (CVE)
°ü·Ã URL 17920 (SecurityFocus)
°ü·Ã URL 26348,26353,26354,26355 (ISS)