English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22168
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle9iAS´Â Á¸ÀçÇÏÁö ¾Ê´Â .jsp ÆÄÀÏÀ» ÅëÇÑ ¹°¸®Àû °æ·Î ³ëÃâ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Oracle »ç¿¡ ÀÇÇØ¼­ ¹èÆ÷µÇ´Â ¾îÇø®ÄÉÀÌ¼Ç ¼­¹ö Oracle9iAS ´Â À¥ ¼­¹ö ¿ëÀ¸·Î Apache À¥ ¼­¹ö, ÀÚ¹Ù ¼­ºí¸´(Java servlet) ¿£Áø°ú ÇÔ²² µ¿ÀÛÇÑ´Ù. ÀÌ Oracle9iAS ¼­¹öÀÇ ÀϺΠ¹öÀü¿¡´Â ¿ø°ÝÁö °ø°ÝÀÚ¿¡°Ô À¥ ¼­¹ö »ó¿¡¼­ ÆÄÀÏÀÇ ¹°¸®Àû °æ·Î¸¦ ³ëÃâÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½ URL °ú °°ÀÌ ¼­¹ö »ó¿¡ Á¸ÀçÇÏÁö ¾Ê´Â ÀÓÀÇÀÇ .jsp È®ÀåÀÚ¸¦ °®´Â JSP ÆÄÀÏÀ» ¿äûÇÒ ¶§ ¹ß»ýÇÑ´Ù.

http://target_server/non_existent_file.jsp

¼­¹ö´Â ÀÌ¿¡ ´ëÇÑ ÀÀ´äÀ¸·Î ´ÙÀ½°ú °°Àº ¿¡·¯ ÆäÀÌÁö¸¦ ¹ÝȯÇϴµ¥, ÀÌ ÆäÀÌÁö ¾È¿¡´Â À¥ ¼­¹ö¿¡ ÀÖ´Â ÆÄÀÏ¿¡ ´ëÇÑ ¹°¸®Àû °æ·Î°¡ ¸í½ÃµÇ¾î ÀÖ´Ù.

JSP Error:
Request URI:/non_existent_file.jsp
Exception:
javax.servlet.ServletException: java.io.FileNotFoundException: /usr/local/oracle_home/Apache/Apache/htdocs/non_existent_file.jsp (No such file or directory)

ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ °ø°Ý ´ë»óÀÌ µÇ´Â ¼­¹öÀÇ ÆÄÀÏ ½Ã½ºÅÛ°ú °ü·ÃµÈ Áß¿äÇÑ Á¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ°í ÀÌ Á¤º¸µéÀ» ±â¹ÝÀ¸·Î º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇϵµ·Ï ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/3341
http://www.iss.net/security_center/static/7135.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æûµé :
Oracle9i Application Server 1.0.0
Oracle9i Application Server 1.0.1
Oracle9i Application Server 1.0.2
ÇØ°áÃ¥ Oracle »çÀÇ À¥ »çÀÌÆ® http://download.oracle.com/otn/utilities_drivers/jsp/ojsp_1120.zip ¸¦ ÂüÁ¶ÇÏ¿© ÀÌ·¯ÇÑ Ãë¾àÁ¡ÀÌ ÇØ°áµÈ OJSP 1.1.2.0.0 À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Àӽà ¹æÆíÀ¸·Î, Oracle Apache/JServ ¼­¹ö¸¦ »ç¿ëÇÒ °æ¿ì ½ÇÁ¦ µð·ºÅ丮 °æ·Î¿Í °¡»ó µð·ºÅ丮 °æ·Î°¡ ´Ù¸¥ Áö ¹Ýµå½Ã È®ÀÎÇÑ´Ù. ¶ÇÇÑ, µ¥ÀÌÅͳª ÆÄÀÏÀ» ÀúÀåÇϱâ À§ÇØ "ApJServMount <servletzonepath> <servletzone>¿¡¼­ <servletzonepath> µð·ºÅ丮¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ÇÑ´Ù.
°ü·Ã URL CVE-2001-1372 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)