English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25059
À§Çèµµ 30
Æ÷Æ® 3306
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 5.0.37 ÀÌÀüÀÇ MySQLÀÇ ¾î¶² ¹öÀüÀÌ °¡µ¿ ÁßÀÌ´Ù. MySQL 5.0.36 ÀÌÀüÀÇ 5.x ¹öÀüµéÀº "ORDER BY" ¹®ÀåÀ» ÅëÇØ Á¤·ÄµÈ ´ÜÀÏ¿­(single-row) subselect ÁúÀǸ¦ ó¸®ÇÒ ¶§ ·ÎÄà °ø°ÝÀÚ°¡ ¼­ºñ½º °ÅºÎ(µ¥ÀÌÅͺ£À̽º Å©·¡½¬)¸¦ À¯¹ßÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ SQL ÁúÀǸ¦ º¸³¿À¸·Î½á, SELECT ¸í·É ±ÇÇÑÀ» °¡Áø ÀÎÁõ¹ÞÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç MySQLÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://bugs.mysql.com/bug.php?id=24630
http://www.sec-consult.com/284.html
http://www.securityfocus.com/archive/1/archive/1/462339/100/0/threaded
http://secunia.com/advisories/24609
http://secunia.com/advisories/24483

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MySQL AB, MySQL 5.0.37 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ MySQL ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://dev.mysql.com/downloads/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â MySQLÀÇ °¡Àå ÃֽŠ¹öÀü(5.0.37 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Ubuntu LinuxÀÇ °æ¿ì:
´ÙÀ½ Ubuntu Security Notice USN-440-1À» ÂüÁ¶ÇÏ¿© MySQLÀÇ ±³Á¤µÈ ÆÐÅ°Áö ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.ubuntu.com/usn/usn-440-1
°ü·Ã URL CVE-2007-1420 (CVE)
°ü·Ã URL 22900 (SecurityFocus)
°ü·Ã URL 32911 (ISS)