Ãë¾àÁ¡ID |
22351 |
À§Çèµµ |
40 |
Æ÷Æ® |
8000, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Icecast ¼ÒÇÁÆ®¿þ¾î´Â XSL Çؼ®±â¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Icecast´Â Windows¿Í Unix °è¿ ¿î¿µÃ¼Á¦ »ó¿¡¼ µ¿ÀÛÇÏ´Â °ø°³ ¼Ò½º mp3 ¹æ¼Û ÇÁ·Î±×·¥ÀÌ´Ù. Icecast 2.20 ÀÌÇÏÀÇ ¹öÀüÀº Á¤º¸ ³ëÃâ°ú ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
1) ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡: XSL Çؼ®±â(Parser)´Â XSLÀÇ 'when', 'if' ±×¸®°í 'value-of' µîÀÇ Å±×(tag)ÀÇ °ªµéÀ» ÇÁ·Î¼¼½º ¸Þ¸ð¸®¿¡ ÀÖ´Â ÇÑÁ¤µÈ ¹öÆÛ·Î º¹»çÇϱâ Àü¿¡ ±× ÅÂ±× °ªµéÀÇ Å©±â¸¦ °Ë»çÇÏÁö ¾Ê´Â´Ù. °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ XSL ÆÄÀÏÀ» Icecast Æú´õ¿¡ ¿Ã·Á ³õÀ» ¼ö¸¸ ÀÖ´Ù¸é ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. 2) Á¤º¸ ³ëÃâ Ãë¾àÁ¡: XSL Çؼ®±â(Parser)´Â XSL ÆÄÀϵ鿡 ´ëÇØ Á¡('.')À¸·Î ³¡³ª´Â ¿äûÀ» ÇÏ°Ô µÇ¸é Çؼ®¿¡ ½ÇÆÐÇÏ°í ´ë½Å¿¡ ÆÄÀÏÀÇ ³»¿ëÀ» º¸¿© ÁØ´Ù. °ø°ÝÀÚ´Â À̸¦ µµ¿ëÇÏ¿© XSL ÆÄÀϵ鿡 Æ÷ÇÔµÈ ¹Î°¨ÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/393705 http://www.securitytracker.com/alerts/2005/Mar/1013475.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Icecast 2.20 ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
IcecastÀÇ À¥ »çÀÌÆ®ÀÎ http://www.icecast.org/download.php ÃֽŹöÀüÀÇ Icecast(2.20 ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-0837,CVE-2005-0838 (CVE) |
°ü·Ã URL |
12849 (SecurityFocus) |
°ü·Ã URL |
19760,19753 (ISS) |
|