English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23068
À§Çèµµ 30
Æ÷Æ® 2401
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CVS
»ó¼¼¼³¸í ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ¼­¹ö´Â Piped Checkout Access Validation Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
CVS (Concurrent Versions System)´Â ´ëºÎºÐÀÇ Linux¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡ Àû¿ë °¡´ÉÇÑ, °ø°³ ¼Ò½ºÀÇ ¼Ò½ºÄÚµå °ü¸® ¹× ¹èÆ÷ ½Ã½ºÅÛÀÌ´Ù. ÀÌ CVS ¼­¹öÀÇ ÀϺΠ¹öÀüµé¿¡´Â piped checkout(Checkout: CVS ¼­¹ö¿¡ ÀÖ´Â ¾î¶² ¸ðµâÀ» ÀÚ½ÅÀÇ ·ÎÄà ÀÛ¾÷ Àå¼Ò·Î °¡Á®¿À´Â ÀÛ¾÷)ÀÇ ºÒÃæºÐÇÑ ÀÔ·Â À¯È¿¼º °Ë»ç(input validation check)·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ ÀÎÁõµÈ °ø°ÝÀڵ鿡°Ô ¼­¹ö »óÀÇ ÀÓÀÇÀÇ RCS(Revision Control System) ÆÄÀϵéÀ» º¼ ¼ö ÀÖµµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¾ÇÀÇÀûÀÎ °ø°ÝÀÚµéÀº '../" µð·ºÅ丮 Ž»ö ½ºÆ®¸µÀ» Æ÷ÇÔÇÑ »ó´ë °æ·Î¸íÀ» »ç¿ëÇÏ¿© ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç CVS ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2004/Apr/1009853.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CVS 1.10.7, 1.10.8
CVS 1.11, 1.11.1 p1, 1.11.1
CVS 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6,
CVS 1.11.10, 1.11.11, 1.11.12, 1.11.13, 1.11.14
CVS 1.12.1, 1.12.2
Linux Any version
UNIX Any version
ÇØ°áÃ¥ ´ÙÀ½ CVS À¥ »çÀÌÆ®¿¡¼­ ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÈ CVSÀÇ ¹öÀü(1.11.15 stable ȤÀº 1.12.7 development)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://ftp.gnu.org/non-gnu/cvs/
°ü·Ã URL CVE-2004-0405 (CVE)
°ü·Ã URL 10140 (SecurityFocus)
°ü·Ã URL (ISS)