English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22146
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹öÀÇ /doc/packages µð·ºÅ丮ÀÇ ³»¿ëÀÌ ¸®½ºÆÃ µÈ´Ù.
¿ÜºÎÀÇ ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ À¥¼­¹ö·Î Ưº°ÇÑ URL ("http://hosts.any/doc/packages/")À» Àü¼ÛÇÔÀ¸·Î½á S.u.S.E 6.3 À̳ª 6.4 ½Ã½ºÅÛ¿¡ ¼³Ä¡µÈ ÆÐŰÁöÀÇ ¸®½ºÆ®¸¦ ¾òÀ» ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â S.u.S.E¿¡ °ø±ÞµÈ Apache httpd.conf ¿¡¼­ ÀÌ À¥ rootÀÇ ¼­ºê µð·ºÅ丮·ÎºÎÅÍ ¹®¼­µéÀ» ¾Æ¹«¿¡°Ô³ª Çã¿ëÇϵµ·Ï ÇÑ ¼³Á¤È¯°æ ¶§¹®ÀÌ´Ù. ÀÌ °á°ú, °ø°ÝÀÚµéÀÌ ´ë»ó ½Ã½ºÅÛ¿¡ ¾î¶² ÆÐŰÁö°¡ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö¸¦ ¾Ë ¼ö ÀÖ°Ô ÇØ ÁÖ¸ç, ´õ Á¤±³ÇÑ °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ´Â µ¥¿¡µµ µµ¿òÀ» ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/1707
http://www.iss.net/security_center/static/5276.php

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
SuSE Linux 6.3, 6.4
ÇØ°áÃ¥ Apache ¼³Á¤ ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© À¥¼­¹ö »óÀÇ /doc µð·ºÅ丮¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Á¦ÇÑÇÏ¿©¾ß ÇÑ´Ù.

Apache ¼³Á¤ ÆÄÀÏÀ» ¼öÁ¤Çϱâ À§Çؼ­´Â:

Apache ¼³Á¤ ÆÄÀÏ (/etc/httpd/httpd.conf)À» ¿­°í ´ÙÀ½ ¹®ÀåÀ» ã´Â´Ù (¶óÀÎ 801):
<Directory /usr/doc>
Options FollowSymLinks Indexes +Includes
AllowOverride None
</Directory>

´ÙÀ½ ¹®ÀåÀ¸·Î ÅØ½ºÆ®¸¦ ±³Ã¼ÇÑ´Ù:
<Directory /usr/doc>
order deny,allow
deny from all
allow from localhost
Options Indexes FollowSymLinks +Includes
AllowOverride None
</Directory>
°ü·Ã URL CVE-2000-1016 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)