English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22401
À§Çèµµ 40
Æ÷Æ® 8019
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Adobe Document/Graphics Server´Â File URIµéÀ» ÅëÇÑ ¸®¼Ò½º ¾×¼¼½º Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Adobe Graphics Server 2.0°ú 2.1 ¹öÀüµé ±×¸®°í Adobe Document Server 5.0°ú 6.0 ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ´ÙÀ½ ÇàÀ§µéÀ» Çã¿ëÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù:

- ÀÓÀÇÀÇ ±×·¡ÇÈ È¤Àº PDF ÆÄÀÏµé ¾×¼¼½º
- ÀÓÀÇÀÇ ±×·¡ÇÈ È¤Àº PDF ÆÄÀϵéÀ» ¼­¹ö¿¡ »ý¼º
- ÄÄÇ»ÅÍ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º ȹµæ
- ÀÓÀÇÀÇ ÄÚµå ½ÇÇà

Ãë¾àÁ¡Àº Æ÷Æ® 8019 »ó¿¡ °¡µ¿ ÁßÀÎ AlterCast À¥ ¼­ºñ½º¸¦ ÅëÇØ File URIµéÀ» ÀÌ¿ëÇÏ¿© ±×·¡ÇÈ È¤Àº PDF ÆÄÀϵéÀ» ¼­¹ö »óÀÇ ÀÓÀÇÀÇ À§Ä¡·ÎºÎÅÍ °Ë»ö ȤÀº ÀúÀåµÉ ¼ö ÀÖµµ·Ï Çã¿ëÇØ ÁÖ´Â "loadContent", "saveContent", ±×¸®°í "saveOptimized" ADS (Adobe Document Server) ¸í·Éµé¿¡ ÀÖ´Ù. ÀÌ´Â ¼­¹öÀÇ "All Users" ½ÃÀÛ Æú´õ·ÎÀÇ ¾ÇÀÇÀûÀÎ JavaScript¸¦ Æ÷ÇÔÇÑ (HTA È®ÀåÀÚ¸¦ °¡Áø) ±×·¡ÇÈ ÆÄÀÏÀ» ÀÛ¼ºÇØ ÁÖ´Â Àß Á¶ÀÛµÈ SOAP ¿äûÀ» º¸³¿À¸·Î½á µµ¿ëµÉ ¼ö ÀÖ´Ù. ¿©±â¼­ÀÇ ±×·¡ÇÈ ÆÄÀÏÀº ¾î¶² »ç¿ëÀÚ°¡ ´ÙÀ½ ¹ø ·Î±×ÀÎ ½Ã¿¡ ½ÇÇàµÇ°Ô µÈ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ­´Â ¼­ºñ½º°¡ Interactive ·Î±×¿Â ±ÇÇÑÀÌ ºÎ¿©µÈ Á¤»ó»ç¿ëÀÚÀÇ ±ÇÇÑÀ̳ª ȤÀº (µðÆúÆ®) SYSTEM ±ÇÇÑÀ» °¡Áö°í ÀÛµ¿Çϵµ·Ï ±¸¼ºµÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/secunia_research/2005-28/advisory/
http://secunia.com/advisories/19229/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Adobe Document Server 5.0, 6.0
Adobe Graphics Server 2.0, 2.1
Microsoft Windows Any version
ÇØ°áÃ¥ Adobe»ç´Â ´õÀÌ»ó Adobe Document/Graphics Server¸¦ ´õ ÀÌ»ó Áö¿øÇÏÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2006-1182 (CVE)
°ü·Ã URL 17113 (SecurityFocus)
°ü·Ã URL 25247 (ISS)