| Ãë¾àÁ¡ID |
22016 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Apache 2.0.x Win32 ¼³Ä¡ÆÇÀº µðÆúÆ® ½ºÅ©¸³Æ®ÀÎ /cgi-bin/test-cgi.bat ÆÄÀÏÀ» žÀçÇϰí Àִµ¥ ÀÌ ÆÄÀÏÀº °ø°ÝÀÚ°¡ ÆÄÀÌÇÁ ¹®ÀÚÀÎ '|'¸¦ ÅëÇØ SYSTEM ±ÇÇÑÀ¸·Î Apache ¼¹ö»óÀÇ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¾ÆÆÄÄ¡ À¥¼¹ö´Â DOS Batch ½ºÅ©¸³Æ®µéÀ» ó¸®ÇÏ´Â ¹æ¹ýÀÇ ¹®Á¦·Î ÀÎÇÏ¿© ÆÄÀÌÇÁ ¹®ÀÚÀÎ '|'¸¦ »ç¿ëÇÏ¿© SYSTEM ±ÇÇÑÀ¸·Î À¥¼¹ö»óÀÇ ¸í·ÉµéÀ» ¿ø°ÝÀ¸·Î ¼öÇà°¡´ÉÇÑ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. 1.3.24 ÀÌÀü, ±×¸®°í 2.0.34-beta ÀÌÀüÀÇ 2.0.x Win32¿ë Apache´Â DOS ¹èÄ¡ (.bat) ȤÀº .cmd ½ºÅ©¸³Æ®¿¡ ´ëÇÑ À¥ ¿äûµéÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ½É°¢ÇÑ ¹®Á¦Á¡À» °¡Áö°í ÀÖ´Ù. DOS ¹èÄ¡ ÆÄÀÏ (.bat ȤÀº .cmd)¿¡ ´ëÇÑ ¿äûÀÌ Apache À¥¼¹ö·Î Àü´ÞµÇ¸é ±× ¼¹ö´Â ½© ÇØ¼®±â (shell interpreter, µðÆúÆ®·Î´Â cmd.exe)¸¦ »ý¼ºÇÏ¿© »ç¿ëÀÚ¿¡ ÀÇÇØ Àü´ÞµÈ ÀμöµéÀ» °¡Áö°í ½ºÅ©¸³Æ®¸¦ ¼öÇà½Ãų °ÍÀÌ´Ù. ±×·¯³ª ÀԷ¿¡ ´ëÇÑ ¾î¶°ÇÑ °ËÁõÀÛ¾÷µµ °ÅÄ¡Áö ¾Ê±â ¶§¹®¿¡ CGI ½ºÅ©¸³Æ®¿¡ ´ëÇÑ Àμö·Î½á ÆÄÀÌÇÁ ¹®ÀÚ ('|')¿¡ ¸í·ÉµéÀÌ µ¡ºÙ¿© º¸³¾ ¼ö°¡ ÀÖÀ¸¸ç, °á±¹ ½¯ ÇØ¼®±â´Â ÀÌ ¸í·ÉµéÀ» ½ÇÇà½ÃŰ°Ô µÈ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/4335 http://marc.theaimsgroup.com/?l=bugtraq&m=101674082427358&w=2
Ãë¾àÇÑ ½Ã½ºÅÛ: * Apache ¹öÀü 1.3.(6~23) win32 * Apache ¹öÀü 2.0.28-BETA win32 (°ø°ÝÀÌ °¡´ÉÇÑ /cgi-bin/test-cgi.bat ÆÄÀÏÀ» µðÆúÆ®·Î Æ÷ÇÔÇÔ) * Apache ¹öÀü 2.0.32 -BETA win32 |
| ÇØ°áÃ¥ |
'test-cgi.bat' CGI ÆÄÀÏ »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é /cgi-bin/ °¡»ó µð·ºÅ丮·ÎºÎÅÍ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
-- ȤÀº --
Apache À¥¼¹ö 1.3.24, ȤÀº °ð Ãâ½ÃµÉ 2.0.34-beta ·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ´ÙÀ½ »çÀÌÆ®¿¡¼ ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ´Ù: http://www.apache.org/dist/httpd/ |
| °ü·Ã URL |
CVE-2002-0061 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|