English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21981
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Dokeos ÇÁ·Î±×·¥Àº 1.6.4 ȤÀº 2.0.3 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Dokeos´Â ÇнÀ °ü¸® ½Ã½ºÅÛÀÌ´Ù. Dokeos 1.6.3 ÀÌÇÏÀÇ ¹öÀüµé°ú Dokeos Community Release 2.0.2 ÀÌÇÏÀÇ ¹öÀüµéÀº 'claroline/exercice/testheaderpage.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'rootSys' Àμö ±×¸®°í 'claroline/resourcelinker/resourcelinker.inc.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'clarolineRepositorySys' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ´ÙÁßÀÇ ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à PHPÀÇ 'register_globals' ¼³Á¤ÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.dokeos.com/forum/viewtopic.php?t=6848
http://www.dokeos.com/wiki/index.php/Security#April_5th.2C_2006
http://secunia.com/advisories/19576/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Dokeos ¹öÀü 1.6.3°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Dokeos ¹öÀü 2.0.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Dokeos ÇнÀ °ü¸® ½Ã½ºÅÛ À¥ »çÀÌÆ®ÀÎ http://www.dokeos.com/download.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Dokeos (1.6.4 ȤÀº ÀÌÈÄ) ȤÀº Dokeos Community Release (2.0.3 ȤÀº ÀÌÈÄ)ÀÇ °¡Àå ÃֽŠ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-2286 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 25740 (ISS)