English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22252
À§Çèµµ 40
Æ÷Æ® 8080,3128
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Webproxy
»ó¼¼¼³¸í ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â ´ÙÁßÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼­¹öÀÌ´Ù. Squid Web Proxy Cache 2.4 STABLE3 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å°°Å³ª ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Ưº°È÷ Á¶ÀÛµÈ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ Æ÷ÇÔÇÑ ftp:// URLÀ» ¿äûÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ã۰í Proxy ¼­ºñ½º°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿µÇâÀ» ¹Þ´Â Squid ¼­¹ö »ó¿¡ ½©(shell)À» ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/613459

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
National Science Foundation Squid Web Proxy Cache 2.4.STABLE3 ±îÁöÀÇ 2.x ¹öÀüµé
FreeBSD 2002-02-19 ÀÌÀüÀÇ Ports Collection
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Squid HTTP Proxy Security Update Advisory 2002:1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.squid-cache.org/Advisories/SQUID-2002_1.txt

Mandrake Linux 7.1, 7.2, 8.0, Corporate Server 1.0.1, ±×¸®°í Single Network Firewall 7.2ÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2002:016-1À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE4-1.5mdk ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Linux Errata Advisory RHSA-2002:029-09¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://rhn.redhat.com/errata/RHSA-2002-029.html

Caldera OpenLinux Server ±×¸®°í Workstation 3.1.1ÀÇ °æ¿ì:
´ÙÀ½ Caldera International »ç, Security Advisory CSSA-2002-010.0À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀü(2.4.STABLE2-3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-010.0.txt

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SuSE-SA:2002:008À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/103706/170/

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ÀÌ ¹®¼­ÀÇ "Âü°í »çÀÌÆ®" ¶õ¿¡ ÀÖ´Â CERT Vulnerability Note VU#613459¸¦ ÂüÁ¶ÇÑ´Ù.
°ü·Ã URL CVE-2002-0068 (CVE)
°ü·Ã URL 4148 (SecurityFocus)
°ü·Ã URL 8258 (ISS)