English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22241
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç thttpd HTTP ¼­¹ö´Â 404 ¿¡·¯ ÆäÀÌÁö¿¡ Cross-Site Scripting Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Acme Labs¿¡ ÀÇÇØ °³¹ßµÈ thttpd´Â ´ëºÎºÐÀÇ Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼­ ÀÌ¿ë °¡´ÉÇÑ ¹«·á À¥ ¼­¹ö µ¥¸óÀÌ´Ù. Thttpd ¹öÀü 2.20b ±×¸®°í ´Ù¸¥ ÀϺΠ¹öÀüµéÀº ¿¡·¯ ÆäÀÌÁöµéÀ» »ý¼ºÇÒ ¶§ URLµéÀÌ ½ºÅ©¸³Æ® ¸í·ÉµéÀ» Æ÷ÇÔÇϰí ÀÖ´Â Áö¸¦ üũÇÏÁö ¾Ê´Â´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URL ¸µÅ©¸¦ »ý¼ºÇÒ ¼ö ÀÖ´Ù. ¸µÅ©°¡ ÀÏ´Ü Å¬¸¯µÇ¸é, ¿¡·¯ ¸Þ½ÃÁö°¡ µð½ºÇ÷¹À̵Ǹ鼭 È£½ºÆÃÇØ ÁÖ´Â »çÀÌÆ®ÀÇ ±ÇÇÑÀ» °¡Áö°í Èñ»ýÀÚÀÇ À¥ ºê¶ó¿ìÀú¿¡¼­ Á¶ÀÛÇÑ ½ºÅ©¸³Æ®°¡ ½ÇÇàµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/vuln-dev/2002-q2/0155.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
thttpd 2.20b
thttpd 2.20c
Unix Any version
Linux Any version
ÇØ°áÃ¥ ÀÌ °áÇÔ¿¡ ´ëÇÑ ÆÐÄ¡´Â ±¸ÇÒ ¼ö ¾ø´Ù. ´ÙÀ½ thttpd À¥ »çÀÌÆ®¿¡¼­ thttpdÀÇ °¡Àå ÃֽйöÀü(2.24 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.acme.com/software/thttpd/
°ü·Ã URL CVE-2002-0733 (CVE)
°ü·Ã URL 4601 (SecurityFocus)
°ü·Ã URL 9029 (ISS)