Ãë¾àÁ¡ID |
22254 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Oracle9iAS Web CacheÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â ´ÙÁßÀÇ °íÀ§Ç輺 Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. OracleÀº Oracle Application Server Web Cache 10g (9.0.4.0.0) ±×¸®°í Oracle9i Application Server Web Cache¿¡ ´ÙÁßÀÇ ¾î¶°ÇÑ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù°í ¹àÇû´Ù. ¸¸¾à Web Cache°¡ ±¸µ¿ ÁßÀÌ¸é¼ ¿øº» À¥ ¼¹öÀÇ À¯Çü°ú´Â »ó°ü¾øÀÌ (¿¹¸¦ µé¾î, Oracle HTTP Server, Apache ȤÀº ´Ù¸¥ À¥ ¼¹öµé), ¾î¶² Ŭ¶óÀÌ¾ðÆ® ¿äûÀ» À§ÇØ Oracle Application Server Web CacheÀÇ listener Æ÷Æ®¿¡ Á¢¼Ó ´ë±âÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ¹Ý¸é¿¡ Ŭ¶óÀÌ¾ðÆ® ¿äûÀÌ ¿øº» Web Cache¸¦ ¿ìȸÇÏ¿© Á÷Á¢ÀûÀ¸·Î À¥ ¼¹ö·Î º¸³»Áø´Ù¸é ÀÌ Ãë¾àÁ¡µéÀÌ µµ¿ëµÇ¾î ÁöÁö´Â ¾Ê´Â´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.oracle.com/technetwork/topics/security/2004alert66-128884.pdf http://www.kb.cert.org/vuls/id/643985 http://www.securityfocus.com/archive/1/359853
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle Application Server Web Cache 10g (9.0.4.0.0) Oracle Oracle9iAS Web Cache 9.0.3.1.0 Oracle Oracle9iAS Web Cache 9.0.2.3.0 Oracle Oracle9iAS Web Cache 2.0.0.4.0 HP Compaq Tru64 UNIX Any version HP-UX Any version IBM AIX Any version Sun Solaris Any version Microsoft Windows Any version Linux Any version Windows, Tru64 ±×¸®°í AIX »óÀÇ Oracle AS Web Cache 10g (9.0.4.0.0)´Â Ãë¾àÇÏÁö ¾ÊÀ½ |
ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. Oracle Application Server Web Cache 10g (9.0.4.0)´Â ÀÌ¹Ì Windows, Tru64 ±×¸®°í AIX ¿¡´Â FixµéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ ¸±¸®Áî¿¡ ´ëÇÑ ´Ù¸¥ Ç÷§ÆûµéÀº ¿©ÀüÈ÷ Ãë¾àÇÏ´Ù. ¸¸¾à FixµéÀ» Æ÷ÇÔÇϰí ÀÖ´Â Ç÷§Æûµé ÁßÀÇ Çϳª¸¦ »ç¿ëÇϰí ÀÖ´Â »ç¿ëÀÚ¶ó¸é ÀÌ ¸±¸®Áî·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¸±¸®Áî¿¡ ´ëÇÑ ´Ù¸¥ FixµéÀº Á¦ÀÛ ÁßÀÎ »óÅÂÀÌ´Ù.
OracleÀº ´Ù¾çÇÑ Ç÷§Æûµé°ú ¸±¸®ÁîµéÀ» À§ÇÑ FixµéÀÌ ÀÌ¿ë °¡´ÉÇÑÁö ±×¸®°í Á¦ÀÛ ÁßÀÎÁö¿¡ ´ëÇØ ÀÚ¼¼ÇÏ°Ô ¸í±âÇÑ Patch Availability Matrix¸¦ ¸±¸®ÁîÇØ ³õ¾Ò´Ù. Á» ´õ ÀÚ¼¼ÇÑ ³»¿ë¿¡ ´ëÇØ¼´Â ´ÙÀ½ Oracle Security Alert #66À» ÅëÇØ ¾Ë¾Æº¼ ¼ö ÀÖ´Ù: http://www.oracle.com/technetwork/topics/security/2004alert66-128884.pdf |
°ü·Ã URL |
CVE-2004-0385 (CVE) |
°ü·Ã URL |
9868 (SecurityFocus) |
°ü·Ã URL |
15463 (ISS) |
|