English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23188
À§Çèµµ 40
Æ÷Æ® 6789
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Daemon
»ó¼¼¼³¸í Sun Java Web ConsoleÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î´Â syslog¿Í °ü·ÃµÈ Format String Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Sun Java Web Console 2.2.2¿¡¼­ 2.2.5 ±îÁöÀÇ ¹öÀüµéÀº libwebconsole_services.so ¶óÀ̺귯¸®¿¡ ÀÖ´Â syslog¿Í °ü·ÃµÈ Format String Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ login ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ÇÀ» Å©·¡½¬ ½ÃÅ°°Å³ª ȤÀº À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/archive/1/466048/100/0/threaded
http://www.nruns.com/security_advisory_sun_java_format_string.php
http://secunia.com/advisories/24927

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Sun Java Web Console 2.2.2
Sun Java Web Console 2.2.3
Sun Java Web Console 2.2.4
Sun Java Web Console 2.2.5
Sun Solaris 10
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://download.oracle.com/sunalerts/1001060.1.html
°ü·Ã URL CVE-2007-1681 (CVE)
°ü·Ã URL 23539 (SecurityFocus)
°ü·Ã URL 33731 (ISS)