English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22990
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ WordPress ´Â 5.7.0 ÀÌÀü ¹öÀüÀÌ¸ç ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.

- ÆÄÀÏÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ´Â »ç¿ëÀÚ(¿¹: ÀÛ¼ºÀÚ)´Â XXE °ø°ÝÀ¸·Î À̾îÁö´Â ¹Ìµð¾î ¶óÀ̺귯¸®ÀÇ XML ±¸¹® ºÐ¼® ¹®Á¦¸¦ ¾Ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. PHP 8À» »ç¿ëÇÏ´Â WordPress ¼³Ä¡°¡ ÇÊ¿äÇÕ´Ï´Ù. XXE °ø°ÝÀÌ ¼º°øÇÏ¸é ³»ºÎ ÆÄÀÏ¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ºÎ ¸±¸®½º¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â ÀÌÀü ¹öÀü°ú ÇÔ²² WordPress ¹öÀü 5.7.1¿¡¼­ ÆÐÄ¡µÇ¾ú½À´Ï´Ù. ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ È°¼ºÈ­µÈ »óÅ·ΠÀ¯ÁöÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. (CVE-2021-29447)

- ¿öµåÇÁ·¹½º ¿¡µðÅÍÀÇ ºí·Ï Áß Çϳª´Â ºñ¹Ð¹øÈ£·Î º¸È£µÈ °Ô½Ã¹°°ú ÆäÀÌÁö¸¦ ³ëÃâ½ÃÅ°´Â ¹æ½ÄÀ¸·Î ¾Ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. À̸¦ À§Çؼ­´Â ÃÖ¼ÒÇÑ ±â¿©ÀÚ ±ÇÇÑÀÌ ÇÊ¿äÇÕ´Ï´Ù. ÀÌ°ÍÀº ºÎ ¸±¸®½º¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â ÀÌÀü ¹öÀü°ú ÇÔ²² WordPress 5.7.1¿¡¼­ ÆÐÄ¡µÇ¾ú½À´Ï´Ù. (CVE-2021-29450)

* Âü°í »çÀÌÆ®:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-pmmh-2f36-wvhq
https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html
https://wordpress.org/news/category/security/ Vendor Advisory
https://www.debian.org/security/2021/dsa-4896
http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html
http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh
https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html
https://wordpress.org/news/category/security/
https://www.debian.org/security/2021/dsa-4896

* ¿µÇâ¹Þ´Â Ç÷§Æû:
WordPress 5.7.0 ÀÌÀü ¹öÀü
Any operating system Any version
ÇØ°áÃ¥ ´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(5.7.0 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù
°ü·Ã URL CVE-2021-29447,CVE-2021-29450 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)