Ãë¾àÁ¡ID |
21972 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Joomla! ÇÁ·Î±×·¥Àº 'PEAR.php' ½ºÅ©¸³Æ®¸¦ ÅëÇÑ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Joomla!´Â PHP·Î Á¦ÀÛµÈ °ø°³ ¼Ò½º ÄÜÅÙÃ÷ °ü¸® ½Ã½ºÅÛÀÌ´Ù. Joomla! 1.0.11 ÀÌÀüÀÇ ¹öÀüµé ȤÀº PHP ¹öÀü 4.4.0°ú ÀÌÀü ¹öÀüµé ±×¸®°í ¹öÀü 5.0.5¿Í ÀÌÀü ¹öÀüµéÀº 'PEAR.php' ½ºÅ©¸³Æ®³ª extract() ȤÀº import_request_variables() ÇÔ¼ö ³»ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_globals ¿É¼ÇÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ ÆÄÀÏ ¾÷·Îµå Çʵ带 °¡Áø multipart/form-data POST ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0647.html http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0934.html http://www.php.net/release_4_4_1.php http://secunia.com/advisories/17371 http://www.hardened-php.net/globals-problem http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml https://rhn.redhat.com/errata/RHSA-2005-831.html https://rhn.redhat.com/errata/RHSA-2005-838.html http://www.securityfocus.com/archive/1/415290 http://www.securityfocus.com/archive/1/415291
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Joomla! 1.0.11 ÀÌÀüÀÇ ¹öÀüµé PHP ¹öÀü 4.4.0°ú ÀÌÀü ¹öÀüµé PHP ¹öÀü 5.0.5¿Í ÀÌÀü ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Joomla! À¥ »çÀÌÆ®ÀÎ http://www.joomla.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Joomla!ÀÇ °¡Àå ÃֽŠ¹öÀü(1.0.11 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
-- ȤÀº --
PHP À¥ »çÀÌÆ®ÀÎ http://www.php.net/downloads.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHPÀÇ °¡Àå ÃֽŠ¹öÀü(4.4.1 ȤÀº ÀÌÈÄ, ȤÀº 5.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-3390 (CVE) |
°ü·Ã URL |
15250,19749 (SecurityFocus) |
°ü·Ã URL |
22920 (ISS) |
|