English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21961
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç SquirrelMail ÆÐÅ°Áö´Â compose.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ ÀÓÀÇÀÇ º¯¼ö µ¤¾î¾²±â Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. SquirrelMailÀº PHP4·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ¸ÞÀÏ ½Ã½ºÅÛÀÌ´Ù. SquirrelMail 1.4.0¿¡¼­ 1.4.7±îÁöÀÇ ¹öÀüµéÀº '/src/compose.php' ½ºÅ©¸³Æ®¿¡ ´ëÇÑ GET ¿äûÀ¸·Î Àü´ÞµÈ ¸¸·áµÈ ¼¼¼ÇÀÇ ºÎÁÖÀÇÇÑ Ã³¸®·Î ÀÎÇÏ¿© ÀÓÀÇÀÇ º¯¼ö µ¤¾î¾²±â Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ¹Î°¨ÇÑ Á¤º¸¸¦ ȹµæÇϰųª ´Ù¸¥ »ç¿ëÀÚÀÇ ¼Ó¼ºÀ̳ª À̸ÞÀÏ Ã·ºÎ ÆÄÀϵéÀ» ÀÐ°í ¾²´Â °ÍÀ¸·Î ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÀ» À§ÇØ ¿ø°ÝÁö À¥ ¸ÞÀÏ ¼­¹ö¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.squirrelmail.org/security/issue/2006-08-11
http://www.squirrelmail.org/patches/sqm1.4.7-expired-post-fix-full.patch
http://www.gulftech.org/?node=research&article_id=00108-08112006
http://secunia.com/advisories/21354

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SquirrelMail Project Team, SquirrelMail 1.4.0¿¡¼­ 1.4.7±îÁöÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀüµé
ÇØ°áÃ¥ SquirrelMailÀÇ ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.squirrelmail.org/download.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SquirrelMailÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.8 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-4019 (CVE)
°ü·Ã URL 19486 (SecurityFocus)
°ü·Ã URL 28365 (ISS)