English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25058
À§Çèµµ 30
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB2
»ó¼¼¼³¸í IBM DB2 UDB ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼­¹ö¿¡´Â ´ÙÁßÀÇ ·ÎÄà ±ÇÇÑ »ó½Â Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. IBM DB2 Universal Database (UDB)ÀÇ 9 Fix Pack 2 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì·Î ÀÎÇÏ¿© ´ÙÁßÀÇ ·ÎÄà ±ÇÇÑ »ó½Â Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ·ÎÄà °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º¸¦ Å©·¡½¬ ½ÃÅ°°Å³ª ȤÀº root ±ÇÇÑÀ» °¡Áö°í È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. ¿©±â¿¡ ´õÇÏ¿©, ¼³Ä¡µÈ ¹öÀüÀº ¶ÇÇÑ ·ÎÄà °ø°ÝÀÚ°¡ ÀûÀýÇÑ ±ÇÇѾøÀÌ µð·ºÅ丮µéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=480
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0521.html
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0523.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 UDB FixPack 15 ÀÌÀüÀÇ ¹öÀü 8.1
IBM DB2 Unix 9 FixPack 2 ÀÌÀüÀÇ ¹öÀüµé
Microsoft Windows Any version
Sun Microsystems »ç, Solaris SPARC ±×¸®°í x86
Hewlett-Packard Company, HP-UX 11i
Linux Any version
IBM AIX 4.0 ±×¸®°í 5L
ÇØ°áÃ¥ ´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Universal Database Fix Pack(9 Fix Pack 2 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-1.ibm.com/support/docview.wss?uid=swg1IY94833
°ü·Ã URL CVE-2007-1086,CVE-2007-1087,CVE-2007-1088 (CVE)
°ü·Ã URL 22677,22729 (SecurityFocus)
°ü·Ã URL 32650,32651,32652 (ISS)