Ãë¾àÁ¡ID |
22251 |
À§Çèµµ |
30 |
Æ÷Æ® |
8080,3128 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Webproxy |
»ó¼¼¼³¸í |
ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â mkdir-only PUT ¿äûÀ» ÅëÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼¹öÀÌ´Ù. Squid Web Proxy Cache 2.2.3°ú 2.4 ½Ã¸®ÁîµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Proxy¸¦ ÅëÇÏ¿© Àß Á¶ÀÛµÈ mkdir-only PUT ¿äûÀ» Åë°ú½ÃÅ´À¸·Î½á, °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â Proxy ¼¹ö°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2001-09/0181.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: National Science Foundation Squid Web Proxy Cache 2.3STABLE5 ±îÁöÀÇ 2.3STABLEx National Science Foundation Squid Web Proxy Cache 2.4.x Unix Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ Squid·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://www.squid-cache.org/Download/mirrors.html
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Security Advisory RHSA-2001:113-03À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://rhn.redhat.com/errata/RHSA-2001-113.html
Debian GNU/Linux 2.2 (potato)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-077-1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.2.5-3.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2001/dsa-077
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SuSE-SA:2001:037À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.linuxsecurity.com/content/view/103453/170/
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2001:088À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2001-0843 (CVE) |
°ü·Ã URL |
3354 (SecurityFocus) |
°ü·Ã URL |
7157 (ISS) |
|