Ãë¾àÁ¡ID |
23068 |
À§Çèµµ |
30 |
Æ÷Æ® |
2401 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CVS |
»ó¼¼¼³¸í |
ÇØ´ç CVS ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ¼¹ö´Â Piped Checkout Access Validation Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. CVS (Concurrent Versions System)´Â ´ëºÎºÐÀÇ Linux¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡ Àû¿ë °¡´ÉÇÑ, °ø°³ ¼Ò½ºÀÇ ¼Ò½ºÄÚµå °ü¸® ¹× ¹èÆ÷ ½Ã½ºÅÛÀÌ´Ù. ÀÌ CVS ¼¹öÀÇ ÀϺΠ¹öÀüµé¿¡´Â piped checkout(Checkout: CVS ¼¹ö¿¡ ÀÖ´Â ¾î¶² ¸ðµâÀ» ÀÚ½ÅÀÇ ·ÎÄà ÀÛ¾÷ Àå¼Ò·Î °¡Á®¿À´Â ÀÛ¾÷)ÀÇ ºÒÃæºÐÇÑ ÀÔ·Â À¯È¿¼º °Ë»ç(input validation check)·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ ÀÎÁõµÈ °ø°ÝÀڵ鿡°Ô ¼¹ö »óÀÇ ÀÓÀÇÀÇ RCS(Revision Control System) ÆÄÀϵéÀ» º¼ ¼ö ÀÖµµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¾ÇÀÇÀûÀÎ °ø°ÝÀÚµéÀº '../" µð·ºÅ丮 Ž»ö ½ºÆ®¸µÀ» Æ÷ÇÔÇÑ »ó´ë °æ·Î¸íÀ» »ç¿ëÇÏ¿© ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç CVS ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Apr/1009853.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: CVS 1.10.7, 1.10.8 CVS 1.11, 1.11.1 p1, 1.11.1 CVS 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6, CVS 1.11.10, 1.11.11, 1.11.12, 1.11.13, 1.11.14 CVS 1.12.1, 1.12.2 Linux Any version UNIX Any version |
ÇØ°áÃ¥ |
´ÙÀ½ CVS À¥ »çÀÌÆ®¿¡¼ ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÈ CVSÀÇ ¹öÀü(1.11.15 stable ȤÀº 1.12.7 development)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://ftp.gnu.org/non-gnu/cvs/ |
°ü·Ã URL |
CVE-2004-0405 (CVE) |
°ü·Ã URL |
10140 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|