English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25057
À§Çèµµ 30
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB2
»ó¼¼¼³¸í IBM DB2 UDB ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â SQLJRA ÆÐŶÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. IBM DB2 Universal Database (UDB)ÀÇ 8.1 Fix Pack 14 ÀÌÀüÀÇ ¹öÀüµéÀº DB2ENGN.DLL¿¡ ÀÖ´Â sqle_db2ra_as_recvrequest ÇÔ¼ö¿¡¼­ÀÇ NULL Æ÷ÀÎÅÍ ÂüÁ¶ ¿À·ù·Î ÀÎÇÏ¿©, ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Àß Á¶ÀÛµÈ SQLJRA ÆÐŶÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ´Â µ¥ÀÌÅͺ£À̽º¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www-1.ibm.com/support/docview.wss?uid=swg24014043
http://www-1.ibm.com/support/docview.wss?uid=swg1IY91847
http://www-1.ibm.com/support/docview.wss?uid=swg1IY86917
http://www.appsecinc.com/resources/alerts/db2/2006-11-30.shtml
http://secunia.com/advisories/23397

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 Universal Database 8.x
Microsoft Windows Any version
Sun Microsystems »ç, Solaris SPARC ±×¸®°í x86
Hewlett-Packard Company, HP-UX 11i
Linux Any version
IBM AIX 4.0 ±×¸®°í 5L
ÇØ°áÃ¥ ´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Universal Database Fix Pack(8.1 Fix Pack 14 ȤÀº 8.2 Fix Pack 7 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-1.ibm.com/support/docview.wss?uid=swg24014043
°ü·Ã URL CVE-2006-6638 (CVE)
°ü·Ã URL 21646 (SecurityFocus)
°ü·Ã URL (ISS)