English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22383
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç GNUMP3d ¼­¹ö´Â ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. GNUMP3d´Â Linux ±â¹ÝÀÇ ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ °ø°³ ¼Ò½º ¿Àµð¿À / ºñµð¿À ½ºÆ®¸®¹Ö ¼­¹öÀÌ´Ù. GNUMP3d 2.9.6 ÀÌÀüÀÇ ¹öÀüµéÀº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ÀÇÇØ Cross-Site Scripting ¹× µð·ºÅ丮 Ž»ö °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

1) 2.9.6 ÀÌÀüÀÇ GNUMP3d¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡Àº "."°ú "//" ½ÃÄö½ºµéÀÌ Á¦°ÅµÈ ÈÄ "/.././" ÇüÅ·Πº¯ÇØ ¹ö¸± ¼ö ÀÖ´Â "/.//..//////././"¿Í °°Àº Àß Á¶ÀÛµÈ ½ÃÄö½ºµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
2) 2.9.6 ÀÌÀüÀÇ GNUMP3d¿¡ ÀÖ´Â Cross-Site Scripting (XSS) Ãë¾àÁ¡µéÀº 404 ¿¡·¯ ÆäÀÌÁöµé ȤÀº ¾Ë·ÁÁ® ÀÖÁö ¾ÊÀº ¹æ¹ýµéÀ» ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®³ª HTMLÀ» ÁÖÀÔÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://lists.gnu.org/archive/html/gnump3d-users/2005-10/msg00013.html
http://savannah.gnu.org/cgi-bin/viewcvs/gnump3d/gnump3d/ChangeLog?rev=1.134&content-type=text/vnd.viewcvs-markup
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0580.html
http://securitytracker.com/id?1015118
http://secunia.com/advisories/17351

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Debiuan Linux, GNUMP3d 2.9.3-1sarge2 ÀÌÀüÀÇ ¹öÀüµé
GNU Project, GNUMP3d 2.9.6 ÀÌÀüÀÇ ¹öÀüµé
Linux Any version
ÇØ°áÃ¥ GNUMP3d À¥ »çÀÌÆ®ÀÎ http://savannah.gnu.org/download/gnump3d/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â GNUMP3dÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.7 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

´ÙÀ½ Debian Security Advisory DSA 877-1À» ÂüÁ¶ÇÏ¿© GNUMP3dÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.3-1sarge2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2005/dsa-877
°ü·Ã URL CVE-2005-3123,CVE-2005-3424,CVE-2005-3425 (CVE)
°ü·Ã URL 15226,15228,15341 (SecurityFocus)
°ü·Ã URL 22902,22903 (ISS)