English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23006
À§Çèµµ 40
Æ÷Æ® 515
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LPD
»ó¼¼¼³¸í ÇØ´ç Lpd ¼­¹ö´Â ºñ Secure Mode·Î dvips¸¦ È£ÃâÇÑ´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î Ãë¾àÇÑ È£½ºÆ®»óÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
'dvips'´Â DVI ¹®¼­µéÀ» PostScript·Î º¯È¯½ÃÄÑ ÁÖ´Â À¯Æ¿¸®Æ¼·Î TeTeX ÅØ½ºÆ® Æ÷¸ËÆÃ(text formatting) ÆÐŰÁöÀÇ ¼±ÅÃÀû ±¸¼º¿ä¼ÒÀÌ´Ù. LPRnG¿Í TeTeX°¡ »ç¿ëµÇ´Â ½Ã½ºÅÛ»ó¿¡ À̸¦ ¼³Ä¡Çß´Ù¸é 'dvips'´Â printfilter¿¡ ÀÇÇØ DVI ¹®¼­°¡ ÇÁ¸°Æ®µÉ ¶§ 'lpd'¿¡ ÀÇÇØ È£ÃâµÉ °ÍÀÌ´Ù. Red Hat Linux 7.0 ÀÌÇÏÀÇ ½Ã½ºÅÛ¿¡ ÀÖ´Â DVI print filter (dvips)ÀÇ µðÆúÆ® ¼³Á¤Àº dvips°¡ lpd¿¡ ÀÇÇØ ½ÇÇàµÉ ¶§ secure mode·Î dvips°¡ ¼öÇàÇÏÁö ¾Ê±â ¶§¹®¿¡ ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ¾ÇÀÇÀûÀÎ ¸í·ÉµéÀ» Æ÷ÇÔÇÑ DVI ÆÄÀÏÀ» ÇÁ¸°Æ® ÇÔÀ¸·Î½á ÀÓÀÇÀÇ ¸í·É¼öÇàÀ» Çã¿ëÇÑ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
RedHat Linux 6.2
RedHat Linux 7.0
RedHat Linux 7.1

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/3241
http://www.redhat.com/support/errata/RHSA-2001-102.html
ÇØ°áÃ¥ Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â DVI ¹®¼­¸¦ À§ÇÑ printfilters¿¡ ÀÖ´Â ¿£Æ®¸®¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ýÀÌ ÀÖ´Ù.

Red Hat ½Ã½ºÅÛ¿¡¼­ /usr/lib/rhs/rhs-printfilters/dvi-to-ps.fpi ÆÄÀÏÀ» ÆíÁýÇÏ¿© 'dvips'ÀÇ ½ÇÇà¹æ¹ýÀÌ ¸í½ÃµÈ ¶óÀÎÀ» ´ÙÀ½°ú °°ÀÌ º¯°æÇÑ´Ù:

dvips -f $DVIPS_OPTIONS < $TMP_FILE À»
dvips -R -f $DVIPS_OPTIONS < $TMP_FILE ·Î.

'-R' Àμö´Â Secure Mode·Î 'dvips'¸¦ ½ÇÇà½ÃŲ´Ù´Â °ÍÀÌ´Ù.
°ü·Ã URL CVE-2001-1002 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)