Ãë¾àÁ¡ID |
22795 |
À§Çèµµ |
10 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â WordPress 4.7.x ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç, wp-includes/pluggable.phpÀÇ wp_mail() ÇÔ¼ö¿¡¼ HTTP È£½ºÆ® Çì´õÀÇ ÀÔ·Â °ªÀÌ SERVER_NAME º¯¼ö·Î ÇÒ´ç µÉ ¶§, SERVER_NAME º¯¼öÀÇ ºÎÀûÀýÇÑ »ç¿ëÀ¸·Î ÀÎÇÑ °áÇÔ¿¡ ÀÇÇØ ¿µÇâÀ» ¹Þ´Â´Ù. ¹Ì ÀÎÁõµÈ ¿ø°Ý °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ Á¦¾î ¾Æ·¡¿¡ ÀÖ´Â SMTP ¼¹öÀÇ ¸ÞÀÏ ¹Ú½º·Î ÃʱâÈ Å°¸¦ Àü¼ÛÇϴ Ư¼ö Á¦ÀÛµÈ 'wp-login.php?action=lostpassword' ¿äûÀ» ÀÌ¿ëÇÏ¿© ÀÓÀÇÀÇ ¾ÏÈ£¸¦ ÃʱâÈÇϱâ À§ÇØ ÀÌ À̽´¸¦ ¾Ç¿ëÇÒ ¼ö ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡Àº ¸ðµç »óȲ¿¡¼ ¹ß»ýÇÏÁö´Â ¾Ê´Â´Ù. Àû¾îµµ ´ÙÀ½ Á¶°Ç Áß Çϳª¸¦ ÃæÁ·½ÃÄÑ¾ß ÇØ´ç Ãë¾àÁ¡ÀÌ Àû¿ëµÈ´Ù.
- °ø°ÝÀÚ´Â ¿À·£ ±â°£ µ¿¾È ÇÇÇØÀÚ°¡ À̸ÞÀÏ ¸Þ½ÃÁö ¼ö½ÅÀ» ¸·À» ¼ö ÀÖ´Ù. (¿¹) 5ÀÏ
- ÇÇÇØÀÚÀÇ À̸ÞÀÏ ½Ã½ºÅÛÀº ¿øº» ¸Þ½ÃÁö¸¦ Æ÷ÇÔÇÑ ÀÚµ¿ ÀÀ´äÀ» º¸³½´Ù
- ÇÇÇØÀÚ´Â ¼öµ¿À¸·Î ¿øº» ¸Þ½ÃÁö¸¦ Æ÷ÇÔÇÑ ´äÀåÀ» ¸¸µç´Ù.
* ÂüÁ¶»çÀÌÆ® : https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html https://core.trac.wordpress.org/ticket/25239 https://httpd.apache.org/docs/2.4/mod/core.html#usecanonicalname
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: WordPress ¹öÀü 4.7.x ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
ÇöÀç ¹ê´õ°¡ Á¦°øÇÏ´Â °ø½Ä ¸±¸®Áî°¡ ¾ø´Ù
SERVER_NAMEÀÌ Á¤Àû °ªÀ¸·Î ±¸¼ºµÇµµ·Ï Á¶Ä¡¸¦ ÃëÇÔÀ¸·Î½á ÀÌ Ãë¾àÁ¡À» ¿ÏÈ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î, Apache ½Ã½ºÅÛ¿¡¼ Apache ±¸¼ºÀÇ UseCanonicalName ¼³Á¤À» »ç¿ë °¡´ÉÇÏ°Ô Çϸé, PHP°¡ °ø°ÝÀÚ°¡ Á¶ÀÛ ÇÒ ¼öÀÖ´Â HTTP È£½ºÆ® ¿äû Çì´õ¿¡ ÀÇÁ¸ÇÏÁö ¾Ê°í, ±¸¼ºµÈ ServerName Áö½Ã¾î °ªÀ» »ç¿ëÇÏ°Ô µÈ´Ù. |
°ü·Ã URL |
CVE-2017-8295 (CVE) |
°ü·Ã URL |
98295 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|