| Ãë¾àÁ¡ID |
25012 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
3306 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
¹öÀü 3.22.31 ÀÌÇÏÀÇ MySQL ¼¹ö°¡ °¡µ¿µÇ°í ÀÖ´Ù. 3.22.31 ÀÌÇÏÀÇ MySQL ¹öÀüµéÀº ¿ÜºÎ Attacker¿¡°Ô ÀÎÁõÀýÂ÷¸¦ ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¹®Á¦°¡ ÀÖ´Â ¹öÀü¿¡¼´Â SQL ¼¹ö³» »ç¿ëÀÚ¸íÀ» ¾Ë°í ÀÖ´Â Attacker°¡ ÆÐ½º¿öµå¸¦ Á¤»óÀûÀ¸·Î ÀÔ·ÂÇÏÁö ¾Ê°íµµ Å×À̺íµéÀ» Access ÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4228.php http://www.mysql.com/documentation/mysql/bychapter/manual_News.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: MySQL 3.22.31 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
| ÇØ°áÃ¥ |
MySQLÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù (3.22.32 ÀÌÈÄ ¹öÀü). ȤÀº ´ÙÀ½°ú °°ÀÌ ¼Ò½º¸¦ ¼öÁ¤ÇÏ¿© ¹ö±×¸¦ FixÇÒ ¼ö ÀÖ´Ù. mysql-xxx/sql/password.c ÆÄÀÏ¿¡¼ "while(*scrambled)" ·çÇÁ¸¦ ã¾Æ¼ ¹Ù·Î ¾Õ¿¡ "if(strlen(scrambled) != strlen(to)) return 1"¸¦ Ãß°¡ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0148 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|