Ãë¾àÁ¡ID |
22146 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥¼¹öÀÇ /doc/packages µð·ºÅ丮ÀÇ ³»¿ëÀÌ ¸®½ºÆÃ µÈ´Ù. ¿ÜºÎÀÇ ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ À¥¼¹ö·Î Ưº°ÇÑ URL ("http://hosts.any/doc/packages/")À» Àü¼ÛÇÔÀ¸·Î½á S.u.S.E 6.3 À̳ª 6.4 ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ ÆÐŰÁöÀÇ ¸®½ºÆ®¸¦ ¾òÀ» ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â S.u.S.E¿¡ °ø±ÞµÈ Apache httpd.conf ¿¡¼ ÀÌ À¥ rootÀÇ ¼ºê µð·ºÅ丮·ÎºÎÅÍ ¹®¼µéÀ» ¾Æ¹«¿¡°Ô³ª Çã¿ëÇϵµ·Ï ÇÑ ¼³Á¤È¯°æ ¶§¹®ÀÌ´Ù. ÀÌ °á°ú, °ø°ÝÀÚµéÀÌ ´ë»ó ½Ã½ºÅÛ¿¡ ¾î¶² ÆÐŰÁö°¡ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö¸¦ ¾Ë ¼ö ÀÖ°Ô ÇØ ÁÖ¸ç, ´õ Á¤±³ÇÑ °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ´Â µ¥¿¡µµ µµ¿òÀ» ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/1707 http://www.iss.net/security_center/static/5276.php
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: SuSE Linux 6.3, 6.4 |
ÇØ°áÃ¥ |
Apache ¼³Á¤ ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© À¥¼¹ö »óÀÇ /doc µð·ºÅ丮¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Á¦ÇÑÇÏ¿©¾ß ÇÑ´Ù.
Apache ¼³Á¤ ÆÄÀÏÀ» ¼öÁ¤Çϱâ À§Çؼ´Â:
Apache ¼³Á¤ ÆÄÀÏ (/etc/httpd/httpd.conf)À» ¿°í ´ÙÀ½ ¹®ÀåÀ» ã´Â´Ù (¶óÀÎ 801): <Directory /usr/doc> Options FollowSymLinks Indexes +Includes AllowOverride None </Directory>
´ÙÀ½ ¹®ÀåÀ¸·Î ÅØ½ºÆ®¸¦ ±³Ã¼ÇÑ´Ù: <Directory /usr/doc> order deny,allow deny from all allow from localhost Options Indexes FollowSymLinks +Includes AllowOverride None </Directory> |
°ü·Ã URL |
CVE-2000-1016 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|