English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25112
À§Çèµµ 30
Æ÷Æ® 523
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB2
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â 9.5 Fix Pack 9 ÀÌÀüÀÇ IBM DB2 UDB ¼­¹öÀÇ ¾î¶² ¹öÀüÀÌ ÇØ´ç È£½ºÆ®¿¡ °¡µ¿ ÁßÀÌ´Ù. IBM DB2 Universal Database (UDB)ÀÇ 9.5 Fix Pack 9 ÀÌÀüÀÇ 9.5 ¹öÀüµéÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

- 'NODES.REG' ÆÄÀÏÀÇ ±ÇÇÑÀÌ world-writable ÀÌ´Ù.

- Á¤ÀǵÇÁö ¾ÊÀº º¤ÅÍÀÇ ¿¡·¯·Î ÀÎÇÏ¿© ¼­ºñ½º °ÅºÎ »óÅ¿¡ ºüÁú¼ö ÀÖ´Ù.

- ¹øµé·Î Á¦°øµÈ IBM Tivoli Monitoring Agent (ITMA)ÀÇ Ãë¾àÁ¡À» ÅëÇÏ¿© ·ÎÄà »ç¿ëÀÚÀÇ ±ÇÇÑÀÌ »ó½ÂµÉ ¼ö ÀÖ´Ù

- DB2 Administration Server(DAS)ÀÇ Á¤ÀǵÇÁö ¾ÊÀº ¿¡·¯·Î ÀÎÇÏ¿© Á¤ÀǵÇÁö ¾ÊÀº º¤Å͸¦ ÅëÇÏ¿© ¼­ºñ½º °ÅºÎ »óÅ¿¡ ºüÁö°Å³ª ±ÇÇÑ »ó½ÂÀÌ ÀϾ ¼ö ÀÖ´Ù.

- DB2's XML feature ¿Í °ü·ÃµÈ Á¤ÀǵÇÁö ¾ÊÀº ¸Þ¼Òµå¸¦ ÅëÇÏ¿© 'PUBLIC'ÀÇ 'CONNECT' ±ÇÇÑÀ» °¡Áø ÀÎÁõµÈ »ç¿ëÀÚ°¡ ¼­ºñ½º °ÅºÎ»óÅ¿¡ ºüÁö°Ô ÇÒ ¼ö ÀÖ´Ù.

- 'CONNECT' ¿Í 'CREATEIN' ±ÇÇÑÀ» °¡Áø µ¥ÀÌÅͺ£À̽ºÀÇ ÀÎÁõµÈ »ç¿ëÀÚ°¡ ºñ Àΰ¡µÈ Å×À̺íÀ» ÀÐÀ» ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www-01.ibm.com/support/docview.wss?uid=swg24032087
http://www-01.ibm.com/support/docview.wss?uid=swg21293566#9
http://www-01.ibm.com/support/docview.wss?uid=swg21586193
http://www-01.ibm.com/support/docview.wss?uid=swg1IC79970
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81379
http://www-01.ibm.com/support/docview.wss?uid=swg1IC81387


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM DB2 UDB 9.5 FixPack 9 ÀÌÀüÀÇ 9.5 ¹öÀüµé
Microsoft Windows Any version
Sun Microsystems »ç, Solaris SPARC ±×¸®°í x86
Hewlett-Packard Company, HP-UX 11i
Linux Any version
IBM AIX 4.0 ±×¸®°í 5L
ÇØ°áÃ¥ DB2 Universal Database 9.5ÀÇ °æ¿ì:
´ÙÀ½ IBM Áö¿ø ¹× ´Ù¿î·Îµå À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ IBM DB2 Universal Database Fix Pack(9.5 Fix Pack 9 ȤÀº ÀÌÈÄ)À» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www-304.ibm.com/support/docview.wss?uid=swg24032087
°ü·Ã URL CVE-2012-0709,CVE-2012-0710,CVE-2012-0711,CVE-2012-0712,CVE-2012-1796 (CVE)
°ü·Ã URL 52326 (SecurityFocus)
°ü·Ã URL (ISS)