Ãë¾àÁ¡ID |
22405 |
À§Çèµµ |
40 |
Æ÷Æ® |
10000 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Webmin/Usermin À¥ ÀÎÅÍÆäÀ̽º´Â ¼¼¼Ç ID Spoofing Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WebminÀº Unix¿Í Linux ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ À¥ ±â¹ÝÀÇ ½Ã½ºÅÛ °ü¸® ÅøÀÌ´Ù. ±×¸®°í UserminÀº ½Ã½ºÅÛ °ü¸®Àڵ麸´Ù´Â ÀÏ¹Ý »ç¿ëÀڵ鿡 ÀÇÇÑ »ç¿ëÀ» À§ÇØ °í¾ÈµÈ WebminÀÇ Ãà¼Ò ¹öÀüÀÌ´Ù. Webmin 1.070 ÀÌÀüÀÇ ¹öÀüµé°ú Usermin 1.000 ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Session ID (SID)¸¦ ¼Ó¿© root ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Webmin/Usermin ÆÐÅ°Áö¿¡ ÀÖ´Â miniserv.pl ½ºÅ©¸³Æ®´Â Basic ÀÎÁõ¿¡¼ »ç¿ëµÈ Base64·Î ÀÎÄÚµùµÈ ¹®ÀÚ¿µé¿¡ ÀÖ´Â CRLF (Carriage Return - Line Feed) ½ÃÄö½ºµé°ú °°Àº ¸ÞŸ ¹®ÀÚµéÀ» ÀûÀýÇÏ°Ô Ã³¸®ÇÏÁö ¸øÇÑ´Ù. "password timeouts" ¿É¼ÇÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ°í Á¤»ó »ç¿ëÀÚ¸íÀ» ¾Ë°í ÀÖÀ» ¶§, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â CRLF¸¦ Æ÷ÇÔÇÑ Base64·Î ÀÎÄÚµùµÈ ÀÎÁõ ¹®ÀÚ¿À» Á¦°øÇÔÀ¸·Î½á Session ID¸¦ ¼ÓÀÌ°í ÀÎÁõÀ» ¿ìȸÇÏ¿© root ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/312911 http://www.securiteam.com/unixfocus/5TP092A75Q.html http://secunia.com/advisories/8115/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Usermin Project, Usermin 1.000 ÀÌÀüÀÇ ¹öÀüµé Webmin Project, Webmin 1.070 ÀÌÀüÀÇ ¹öÀüµé Unix Any version Linux Any version |
ÇØ°áÃ¥ |
Webmin À¥ »çÀÌÆ®ÀÎ http://www.webmin.com/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Webmin / UserminÀÇ °¡Àå ÃֽŠ¹öÀü(Webmin 1.070 ȤÀº Usermin 1.000 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
HP-UX 11.00, 11.11, 11.20, ±×¸®°í 11.22ÀÇ °æ¿ì: ´ÙÀ½ Hewlett-Packard Company Security Bulletin HPSBUX0303-250¸¦ ÂüÁ¶ÇÏ¿© º¸¾È Fix¸¦ °¡Áø webminÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://archives.neohapsis.com/archives/hp/2003-q1/0063.html
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2003-0101 (CVE) |
°ü·Ã URL |
6915 (SecurityFocus) |
°ü·Ã URL |
11390 (ISS) |
|