Ãë¾àÁ¡ID |
22252 |
À§Çèµµ |
40 |
Æ÷Æ® |
8080,3128 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Webproxy |
»ó¼¼¼³¸í |
ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼¹öÀÌ´Ù. Squid Web Proxy Cache 2.4 STABLE3 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Ưº°È÷ Á¶ÀÛµÈ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ Æ÷ÇÔÇÑ ftp:// URLÀ» ¿äûÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ã۰í Proxy ¼ºñ½º°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â Squid ¼¹ö »ó¿¡ ½©(shell)À» ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/613459
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: National Science Foundation Squid Web Proxy Cache 2.4.STABLE3 ±îÁöÀÇ 2.x ¹öÀüµé FreeBSD 2002-02-19 ÀÌÀüÀÇ Ports Collection Unix Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Squid HTTP Proxy Security Update Advisory 2002:1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.squid-cache.org/Advisories/SQUID-2002_1.txt
Mandrake Linux 7.1, 7.2, 8.0, Corporate Server 1.0.1, ±×¸®°í Single Network Firewall 7.2ÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2002:016-1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE4-1.5mdk ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Linux Errata Advisory RHSA-2002:029-09¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://rhn.redhat.com/errata/RHSA-2002-029.html
Caldera OpenLinux Server ±×¸®°í Workstation 3.1.1ÀÇ °æ¿ì: ´ÙÀ½ Caldera International »ç, Security Advisory CSSA-2002-010.0À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE2-3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-010.0.txt
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SuSE-SA:2002:008À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.linuxsecurity.com/content/view/103706/170/
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ÀÌ ¹®¼ÀÇ "Âü°í »çÀÌÆ®" ¶õ¿¡ ÀÖ´Â CERT Vulnerability Note VU#613459¸¦ ÂüÁ¶ÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-0068 (CVE) |
°ü·Ã URL |
4148 (SecurityFocus) |
°ü·Ã URL |
8258 (ISS) |
|