English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22351
À§Çèµµ 40
Æ÷Æ® 8000, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Icecast ¼ÒÇÁÆ®¿þ¾î´Â XSL Çؼ®±â¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Icecast´Â Windows¿Í Unix °è¿­ ¿î¿µÃ¼Á¦ »ó¿¡¼­ µ¿ÀÛÇÏ´Â °ø°³ ¼Ò½º mp3 ¹æ¼Û ÇÁ·Î±×·¥ÀÌ´Ù. Icecast 2.20 ÀÌÇÏÀÇ ¹öÀüÀº Á¤º¸ ³ëÃâ°ú ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.

1) ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡: XSL Çؼ®±â(Parser)´Â XSLÀÇ 'when', 'if' ±×¸®°í 'value-of' µîÀÇ Å±×(tag)ÀÇ °ªµéÀ» ÇÁ·Î¼¼½º ¸Þ¸ð¸®¿¡ ÀÖ´Â ÇÑÁ¤µÈ ¹öÆÛ·Î º¹»çÇϱâ Àü¿¡ ±× ÅÂ±× °ªµéÀÇ Å©±â¸¦ °Ë»çÇÏÁö ¾Ê´Â´Ù. °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ XSL ÆÄÀÏÀ» Icecast Æú´õ¿¡ ¿Ã·Á ³õÀ» ¼ö¸¸ ÀÖ´Ù¸é ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
2) Á¤º¸ ³ëÃâ Ãë¾àÁ¡: XSL Çؼ®±â(Parser)´Â XSL ÆÄÀϵ鿡 ´ëÇØ Á¡('.')À¸·Î ³¡³ª´Â ¿äûÀ» ÇÏ°Ô µÇ¸é Çؼ®¿¡ ½ÇÆÐÇÏ°í ´ë½Å¿¡ ÆÄÀÏÀÇ ³»¿ëÀ» º¸¿© ÁØ´Ù. °ø°ÝÀÚ´Â À̸¦ µµ¿ëÇÏ¿© XSL ÆÄÀϵ鿡 Æ÷ÇÔµÈ ¹Î°¨ÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/393705
http://www.securitytracker.com/alerts/2005/Mar/1013475.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Icecast 2.20 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ IcecastÀÇ À¥ »çÀÌÆ®ÀÎ http://www.icecast.org/download.php ÃֽŹöÀüÀÇ Icecast(2.20 ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-0837,CVE-2005-0838 (CVE)
°ü·Ã URL 12849 (SecurityFocus)
°ü·Ã URL 19760,19753 (ISS)