English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25012
À§Çèµµ 30
Æ÷Æ® 3306
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ¹öÀü 3.22.31 ÀÌÇÏÀÇ MySQL ¼­¹ö°¡ °¡µ¿µÇ°í ÀÖ´Ù.
3.22.31 ÀÌÇÏÀÇ MySQL ¹öÀüµéÀº ¿ÜºÎ Attacker¿¡°Ô ÀÎÁõÀýÂ÷¸¦ ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¹®Á¦°¡ ÀÖ´Â ¹öÀü¿¡¼­´Â SQL ¼­¹ö³» »ç¿ëÀÚ¸íÀ» ¾Ë°í ÀÖ´Â Attacker°¡ ÆÐ½º¿öµå¸¦ Á¤»óÀûÀ¸·Î ÀÔ·ÂÇÏÁö ¾Ê°íµµ Å×À̺íµéÀ» Access ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4228.php
http://www.mysql.com/documentation/mysql/bychapter/manual_News.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MySQL 3.22.31 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ MySQLÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù (3.22.32 ÀÌÈÄ ¹öÀü).
ȤÀº ´ÙÀ½°ú °°ÀÌ ¼Ò½º¸¦ ¼öÁ¤ÇÏ¿© ¹ö±×¸¦ FixÇÒ ¼ö ÀÖ´Ù.
mysql-xxx/sql/password.c ÆÄÀÏ¿¡¼­ "while(*scrambled)" ·çÇÁ¸¦ ã¾Æ¼­ ¹Ù·Î ¾Õ¿¡ "if(strlen(scrambled) != strlen(to)) return 1"¸¦ Ãß°¡ÇÑ´Ù.
°ü·Ã URL CVE-2000-0148 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)