Ãë¾àÁ¡ID |
22428 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Mono XSP ¼¹ö´Â '%20'À¸·Î ³¡³ª´Â HTTP ¿äûÀ» ÅëÇÑ ¼Ò½º ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mono XSP ASP.NET ¼¹ö´Â ASP.NET ¾îÇø®ÄÉÀ̼ǵéÀ» È£½ºÆÃÇϱâ À§ÇÑ °æ·®±Þ À¥ ¼¹öÀÌ´Ù. Mono XSP ASP.NET ¼¹ö 1.1¿¡¼ 2.0±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â System.Web Ŭ·¡½º´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ URLÀÇ ³¡¿¡ "%20"À» µ¡ºÙÀÓÀ¸·Î½á ¿äûµÈ ÆÄÀÏÀÇ ¼Ò½º Äڵ带 º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* References: http://www.securityfocus.com/archive/1/454962/30/0/threaded http://secunia.com/advisories/23432/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ASP.NET, Mono XSP ASP.NET Server 1.1¿¡¼ 2.0±îÁöÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
SUSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SUSE Security Announcement SUSE-SA:2007:002¸¦ ÂüÁ¶ÇÏ¿© mono-webÀÇ ÀûÀýÇÑ ±³Á¤µÈ ÆÐÅ°ÁöµéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://lists.opensuse.org/opensuse-security-announce/2007-01/msg00017.html
Mandriva LinuxÀÇ °æ¿ì: ´ÙÀ½ Mandriva Security Advisory MDKSA-2006:234À» ÂüÁ¶ÇÏ¿© mono webÀÇ ¾î¶² ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/security/advisories?name=MDKSA-2006:234
Ubuntu LinuxÀÇ °æ¿ì: ´ÙÀ½ Ubuntu Security Notice USN-397-1À» ÂüÁ¶ÇÏ¿© mono webÀÇ ¾î¶² ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.ubuntu.com/usn/usn-397-1
±âŸ Ç÷§ÆûÀÇ °æ¿ì: Mono Project ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.mono-project.com/Downloads ¿¡¼ ÃֽŹöÀüÀÇ Mono XSP ASP.NET Server·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-6104 (CVE) |
°ü·Ã URL |
21687 (SecurityFocus) |
°ü·Ã URL |
31010 (ISS) |
|