Ãë¾àÁ¡ID |
23188 |
À§Çèµµ |
40 |
Æ÷Æ® |
6789 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Daemon |
»ó¼¼¼³¸í |
Sun Java Web ConsoleÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î´Â syslog¿Í °ü·ÃµÈ Format String Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Sun Java Web Console 2.2.2¿¡¼ 2.2.5 ±îÁöÀÇ ¹öÀüµéÀº libwebconsole_services.so ¶óÀ̺귯¸®¿¡ ÀÖ´Â syslog¿Í °ü·ÃµÈ Format String Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ login ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ÇÀ» Å©·¡½¬ ½ÃÅ°°Å³ª ȤÀº À¥ ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/archive/1/466048/100/0/threaded http://www.nruns.com/security_advisory_sun_java_format_string.php http://secunia.com/advisories/24927
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sun Java Web Console 2.2.2 Sun Java Web Console 2.2.3 Sun Java Web Console 2.2.4 Sun Java Web Console 2.2.5 Sun Solaris 10 |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.oracle.com/sunalerts/1001060.1.html |
°ü·Ã URL |
CVE-2007-1681 (CVE) |
°ü·Ã URL |
23539 (SecurityFocus) |
°ü·Ã URL |
33731 (ISS) |
|