English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22428
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Mono XSP ¼­¹ö´Â '%20'À¸·Î ³¡³ª´Â HTTP ¿äûÀ» ÅëÇÑ ¼Ò½º ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mono XSP ASP.NET ¼­¹ö´Â ASP.NET ¾îÇø®ÄÉÀ̼ǵéÀ» È£½ºÆÃÇϱâ À§ÇÑ °æ·®±Þ À¥ ¼­¹öÀÌ´Ù. Mono XSP ASP.NET ¼­¹ö 1.1¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â System.Web Ŭ·¡½º´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ URLÀÇ ³¡¿¡ "%20"À» µ¡ºÙÀÓÀ¸·Î½á ¿äûµÈ ÆÄÀÏÀÇ ¼Ò½º Äڵ带 º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* References:
http://www.securityfocus.com/archive/1/454962/30/0/threaded
http://secunia.com/advisories/23432/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
ASP.NET, Mono XSP ASP.NET Server 1.1¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SUSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SUSE Security Announcement SUSE-SA:2007:002¸¦ ÂüÁ¶ÇÏ¿© mono-webÀÇ ÀûÀýÇÑ ±³Á¤µÈ ÆÐÅ°ÁöµéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://lists.opensuse.org/opensuse-security-announce/2007-01/msg00017.html

Mandriva LinuxÀÇ °æ¿ì:
´ÙÀ½ Mandriva Security Advisory MDKSA-2006:234À» ÂüÁ¶ÇÏ¿© mono webÀÇ ¾î¶² ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/security/advisories?name=MDKSA-2006:234

Ubuntu LinuxÀÇ °æ¿ì:
´ÙÀ½ Ubuntu Security Notice USN-397-1À» ÂüÁ¶ÇÏ¿© mono webÀÇ ¾î¶² ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.ubuntu.com/usn/usn-397-1

±âŸ Ç÷§ÆûÀÇ °æ¿ì:
Mono Project ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.mono-project.com/Downloads ¿¡¼­ ÃֽŹöÀüÀÇ Mono XSP ASP.NET Server·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-6104 (CVE)
°ü·Ã URL 21687 (SecurityFocus)
°ü·Ã URL 31010 (ISS)