Ãë¾àÁ¡ID |
22383 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç GNUMP3d ¼¹ö´Â ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. GNUMP3d´Â Linux ±â¹ÝÀÇ ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ °ø°³ ¼Ò½º ¿Àµð¿À / ºñµð¿À ½ºÆ®¸®¹Ö ¼¹öÀÌ´Ù. GNUMP3d 2.9.6 ÀÌÀüÀÇ ¹öÀüµéÀº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ÀÇÇØ Cross-Site Scripting ¹× µð·ºÅ丮 Ž»ö °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
1) 2.9.6 ÀÌÀüÀÇ GNUMP3d¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº "."°ú "//" ½ÃÄö½ºµéÀÌ Á¦°ÅµÈ ÈÄ "/.././" ÇüÅ·Πº¯ÇØ ¹ö¸± ¼ö ÀÖ´Â "/.//..//////././"¿Í °°Àº Àß Á¶ÀÛµÈ ½ÃÄö½ºµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. 2) 2.9.6 ÀÌÀüÀÇ GNUMP3d¿¡ ÀÖ´Â Cross-Site Scripting (XSS) Ãë¾àÁ¡µéÀº 404 ¿¡·¯ ÆäÀÌÁöµé ȤÀº ¾Ë·ÁÁ® ÀÖÁö ¾ÊÀº ¹æ¹ýµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://lists.gnu.org/archive/html/gnump3d-users/2005-10/msg00013.html http://savannah.gnu.org/cgi-bin/viewcvs/gnump3d/gnump3d/ChangeLog?rev=1.134&content-type=text/vnd.viewcvs-markup http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0580.html http://securitytracker.com/id?1015118 http://secunia.com/advisories/17351
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Debiuan Linux, GNUMP3d 2.9.3-1sarge2 ÀÌÀüÀÇ ¹öÀüµé GNU Project, GNUMP3d 2.9.6 ÀÌÀüÀÇ ¹öÀüµé Linux Any version |
ÇØ°áÃ¥ |
GNUMP3d À¥ »çÀÌÆ®ÀÎ http://savannah.gnu.org/download/gnump3d/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â GNUMP3dÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
´ÙÀ½ Debian Security Advisory DSA 877-1À» ÂüÁ¶ÇÏ¿© GNUMP3dÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.3-1sarge2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2005/dsa-877 |
°ü·Ã URL |
CVE-2005-3123,CVE-2005-3424,CVE-2005-3425 (CVE) |
°ü·Ã URL |
15226,15228,15341 (SecurityFocus) |
°ü·Ã URL |
22902,22903 (ISS) |
|