English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22251
À§Çèµµ 30
Æ÷Æ® 8080,3128
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Webproxy
»ó¼¼¼³¸í ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â mkdir-only PUT ¿äûÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼­¹öÀÌ´Ù. Squid Web Proxy Cache 2.2.3°ú 2.4 ½Ã¸®ÁîµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Proxy¸¦ ÅëÇÏ¿© Àß Á¶ÀÛµÈ mkdir-only PUT ¿äûÀ» Åë°ú½ÃÅ´À¸·Î½á, °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â Proxy ¼­¹ö°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2001-09/0181.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
National Science Foundation Squid Web Proxy Cache 2.3STABLE5 ±îÁöÀÇ 2.3STABLEx
National Science Foundation Squid Web Proxy Cache 2.4.x
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ Squid·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.squid-cache.org/Download/mirrors.html

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2001:113-03À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://rhn.redhat.com/errata/RHSA-2001-113.html

Debian GNU/Linux 2.2 (potato)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-077-1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.2.5-3.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2001/dsa-077

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SuSE-SA:2001:037À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/103453/170/

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2001:088À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2001-0843 (CVE)
°ü·Ã URL 3354 (SecurityFocus)
°ü·Ã URL 7157 (ISS)