Ãë¾àÁ¡ID |
22401 |
À§Çèµµ |
40 |
Æ÷Æ® |
8019 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Adobe Document/Graphics Server´Â File URIµéÀ» ÅëÇÑ ¸®¼Ò½º ¾×¼¼½º Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Adobe Graphics Server 2.0°ú 2.1 ¹öÀüµé ±×¸®°í Adobe Document Server 5.0°ú 6.0 ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ´ÙÀ½ ÇàÀ§µéÀ» Çã¿ëÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù:
- ÀÓÀÇÀÇ ±×·¡ÇÈ È¤Àº PDF ÆÄÀÏµé ¾×¼¼½º - ÀÓÀÇÀÇ ±×·¡ÇÈ È¤Àº PDF ÆÄÀϵéÀ» ¼¹ö¿¡ »ý¼º - ÄÄÇ»ÅÍ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º ȹµæ - ÀÓÀÇÀÇ ÄÚµå ½ÇÇà
Ãë¾àÁ¡Àº Æ÷Æ® 8019 »ó¿¡ °¡µ¿ ÁßÀÎ AlterCast À¥ ¼ºñ½º¸¦ ÅëÇØ File URIµéÀ» ÀÌ¿ëÇÏ¿© ±×·¡ÇÈ È¤Àº PDF ÆÄÀϵéÀ» ¼¹ö »óÀÇ ÀÓÀÇÀÇ À§Ä¡·ÎºÎÅÍ °Ë»ö ȤÀº ÀúÀåµÉ ¼ö ÀÖµµ·Ï Çã¿ëÇØ ÁÖ´Â "loadContent", "saveContent", ±×¸®°í "saveOptimized" ADS (Adobe Document Server) ¸í·Éµé¿¡ ÀÖ´Ù. ÀÌ´Â ¼¹öÀÇ "All Users" ½ÃÀÛ Æú´õ·ÎÀÇ ¾ÇÀÇÀûÀÎ JavaScript¸¦ Æ÷ÇÔÇÑ (HTA È®ÀåÀÚ¸¦ °¡Áø) ±×·¡ÇÈ ÆÄÀÏÀ» ÀÛ¼ºÇØ ÁÖ´Â Àß Á¶ÀÛµÈ SOAP ¿äûÀ» º¸³¿À¸·Î½á µµ¿ëµÉ ¼ö ÀÖ´Ù. ¿©±â¼ÀÇ ±×·¡ÇÈ ÆÄÀÏÀº ¾î¶² »ç¿ëÀÚ°¡ ´ÙÀ½ ¹ø ·Î±×ÀÎ ½Ã¿¡ ½ÇÇàµÇ°Ô µÈ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ´Â ¼ºñ½º°¡ Interactive ·Î±×¿Â ±ÇÇÑÀÌ ºÎ¿©µÈ Á¤»ó»ç¿ëÀÚÀÇ ±ÇÇÑÀ̳ª ȤÀº (µðÆúÆ®) SYSTEM ±ÇÇÑÀ» °¡Áö°í ÀÛµ¿Çϵµ·Ï ±¸¼ºµÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/secunia_research/2005-28/advisory/ http://secunia.com/advisories/19229/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Adobe Document Server 5.0, 6.0 Adobe Graphics Server 2.0, 2.1 Microsoft Windows Any version |
ÇØ°áÃ¥ |
Adobe»ç´Â ´õÀÌ»ó Adobe Document/Graphics Server¸¦ ´õ ÀÌ»ó Áö¿øÇÏÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-1182 (CVE) |
°ü·Ã URL |
17113 (SecurityFocus) |
°ü·Ã URL |
25247 (ISS) |
|