English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22242
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç thttpd HTTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¿¡ µû¸£¸é ¼­¹ö´Â defang ÇÔ¼ö¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Acme Labs¿¡ ÀÇÇØ °³¹ßµÈ thttpd´Â ´ëºÎºÐÀÇ Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦¿¡¼­ ÀÌ¿ë °¡´ÉÇÑ ¹«·á À¥ ¼­¹ö µ¥¸óÀÌ´Ù. Thttpd ¹öÀü 2.21¿¡¼­ 2.23b1 ±îÁöÀÇ ¹öÀüµéÀº libhttpd.c ÆÄÀÏÀÇ defang ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-10/0272.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
thttpd 2.21¿¡¼­ 2.23b1 ±îÁöÀÇ ¹öÀü
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ thttpd À¥ »çÀÌÆ®¿¡¼­ thttpdÀÇ °¡Àå ÃֽйöÀü(2.24 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.acme.com/software/thttpd/

Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¾È DSA-396-1À» ÂüÁ¶ÇÏ¿© thttpdÀÇ °¡Àå ÃֽŠÆÐŰÁö(2.21b-11.2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2003/dsa-396.en.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È°øÁö SuSE-SA:2003:044¸¦ ÂüÁ¶ÇÏ¿© thttpdÀÇ °¡Àå ÃֽŠÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2003_044_thttpd.html

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2003-0899 (CVE)
°ü·Ã URL 8906 (SecurityFocus)
°ü·Ã URL 13530 (ISS)