English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22254
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle9iAS Web CacheÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â ´ÙÁßÀÇ °íÀ§Ç輺 Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
OracleÀº Oracle Application Server Web Cache 10g (9.0.4.0.0) ±×¸®°í Oracle9i Application Server Web Cache¿¡ ´ÙÁßÀÇ ¾î¶°ÇÑ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù°í ¹àÇû´Ù. ¸¸¾à Web Cache°¡ ±¸µ¿ ÁßÀ̸鼭 ¿øº» À¥ ¼­¹öÀÇ À¯Çü°ú´Â »ó°ü¾øÀÌ (¿¹¸¦ µé¾î, Oracle HTTP Server, Apache ȤÀº ´Ù¸¥ À¥ ¼­¹öµé), ¾î¶² Ŭ¶óÀÌ¾ðÆ® ¿äûÀ» À§ÇØ Oracle Application Server Web CacheÀÇ listener Æ÷Æ®¿¡ Á¢¼Ó ´ë±âÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ¹Ý¸é¿¡ Ŭ¶óÀÌ¾ðÆ® ¿äûÀÌ ¿øº» Web Cache¸¦ ¿ìȸÇÏ¿© Á÷Á¢ÀûÀ¸·Î À¥ ¼­¹ö·Î º¸³»Áø´Ù¸é ÀÌ Ãë¾àÁ¡µéÀÌ µµ¿ëµÇ¾î ÁöÁö´Â ¾Ê´Â´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.oracle.com/technetwork/topics/security/2004alert66-128884.pdf
http://www.kb.cert.org/vuls/id/643985
http://www.securityfocus.com/archive/1/359853

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Application Server Web Cache 10g (9.0.4.0.0)
Oracle Oracle9iAS Web Cache 9.0.3.1.0
Oracle Oracle9iAS Web Cache 9.0.2.3.0
Oracle Oracle9iAS Web Cache 2.0.0.4.0
HP Compaq Tru64 UNIX Any version
HP-UX Any version
IBM AIX Any version
Sun Solaris Any version
Microsoft Windows Any version
Linux Any version
Windows, Tru64 ±×¸®°í AIX »óÀÇ Oracle AS Web Cache 10g (9.0.4.0.0)´Â Ãë¾àÇÏÁö ¾ÊÀ½
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
Oracle Application Server Web Cache 10g (9.0.4.0)´Â ÀÌ¹Ì Windows, Tru64 ±×¸®°í AIX ¿¡´Â FixµéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ ¸±¸®Áî¿¡ ´ëÇÑ ´Ù¸¥ Ç÷§ÆûµéÀº ¿©ÀüÈ÷ Ãë¾àÇÏ´Ù. ¸¸¾à FixµéÀ» Æ÷ÇÔÇϰí ÀÖ´Â Ç÷§Æûµé ÁßÀÇ Çϳª¸¦ »ç¿ëÇϰí ÀÖ´Â »ç¿ëÀÚ¶ó¸é ÀÌ ¸±¸®Áî·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¸±¸®Áî¿¡ ´ëÇÑ ´Ù¸¥ FixµéÀº Á¦ÀÛ ÁßÀÎ »óÅÂÀÌ´Ù.

OracleÀº ´Ù¾çÇÑ Ç÷§Æûµé°ú ¸±¸®ÁîµéÀ» À§ÇÑ FixµéÀÌ ÀÌ¿ë °¡´ÉÇÑÁö ±×¸®°í Á¦ÀÛ ÁßÀÎÁö¿¡ ´ëÇØ ÀÚ¼¼ÇÏ°Ô ¸í±âÇÑ Patch Availability Matrix¸¦ ¸±¸®ÁîÇØ ³õ¾Ò´Ù. Á» ´õ ÀÚ¼¼ÇÑ ³»¿ë¿¡ ´ëÇØ¼­´Â ´ÙÀ½ Oracle Security Alert #66À» ÅëÇØ ¾Ë¾Æº¼ ¼ö ÀÖ´Ù:
http://www.oracle.com/technetwork/topics/security/2004alert66-128884.pdf
°ü·Ã URL CVE-2004-0385 (CVE)
°ü·Ã URL 9868 (SecurityFocus)
°ü·Ã URL 15463 (ISS)