Ãë¾àÁ¡ID |
22264 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache À¥ ¼¹öÀÇ ¹è³ÊÁ¤º¸¿¡ µû¸£¸é, ¼¹ö´Â ¿¡·¯ ·Î±× Escape Sequence Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀϹÝÀûÀ¸·Î "Escape Sequence"´Â ÇÁ¸°Åͳª ¸ð´ÏÅÍ¿Í °°Àº Display ÀåÄ¡µéÀÇ È¸é ¼Ó¼ºµéÀ» Á¦¾îÇϱâ À§ÇØ »ç¿ëµÇ´Â, ASCII ESC(Escape:0x1B)¹®ÀÚ·Î ½ÃÀÛÇÏ´Â ¹®ÀÚ¿ ¹À½À¸·Î¼, µÚ¿¡ Ư¼öÇÑ ¹®ÀÚ¿ÀÌ Ãß°¡ÀûÀ¸·Î µû¸£°Ô µÈ´Ù. ÀϺΠApache ¼¹ö ¹öÀüÀº ¿¡·¯ ·Î±×·ÎºÎÅÍ escape sequence¸¦ ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿©, escape sequenceµéÀÌ Apache ·Î±× ÆÄÀϵ鿡 »ðÀԵǴ °ÍÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚµéÀÌ escape sequence °ü·Ã Ãë¾àÁ¡µéÀ» ¾È°í ÀÖ´Â ¸¹Àº Å͹̳Π¿¡¹Ä·¹ÀÌÅÍ ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö(Terminal Emulator software package)¸¦ »ç¿ëÇÏ¿© ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇØ º¸´Ù ½±°Ô °ø°ÝÀ» ¼öÇàÇϵµ·Ï µµ¿ÍÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¸é ¼ºñ½º °ÅºÎ(Denial of Service) °ø°Ý, ÆÄÀÏ º¯°æ, µ¥ÀÌÅÍ º¯°æ, ÀÓÀÇÀÇ ¸í·É ½ÇÇà µîÀÇ °ø°ÝÀÌ °¡´ÉÇÏ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache Software Foundation Apache HTTP Server 1.3.x Apache Software Foundation Apache HTTP Server 2.0.x Red Hat Linux 7.1, 7.2, 7.3, 8.0, 9 Mandrake Linux 10.0, 9.1, 9.2, Corporate Server 2.1, Multi Network Firewall 8.2 Slackware Linux 8.1, 9.0, 9.1, current Trustix: Trustix Secure Linux 1.5, 2.0, 2.1 Turbolinux 10 Desktop Conectiva Linux 8.0, 9.0 IRIX 2.2.1, 2.3 Windows, Linux, Unix : Any version |
ÇØ°áÃ¥ |
Apache HTTP Server 1.3.x ±×¸®°í 2.0.xÀÇ °æ¿ì: ´ÙÀ½ Apache Software FoundationÀÇ ´Ù¿î·Îµå »çÀÌÆ®, http://httpd.apache.org ¸¦ ÂüÁ¶ÇÏ¿© Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(1.3.31 ÀÌ»ó ¶Ç´Â 2.0.49 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
RedHat ¸®´ª½º 7.x and 8.0, 9ÀÇ °æ¿ì: ´ÙÀ½ Red HatÀÇ Security Advisory RHSA-2003:139-07 ¿Í RHSA-2003:243-07¸¦ ÂüÁ¶ÇÏ¿© Apache(httpd) ÆÐŰÁöÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2003-243.html https://rhn.redhat.com/errata/RHSA-2003-139.html
Mandrake ¸®´ª½ºÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoftÀÇ Security Advisory MDKSA-2004:046¸¦ ÂüÁ¶ÇÏ¿© Apache ÆÐŰÁöÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
±âŸ: ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0020 (CVE) |
°ü·Ã URL |
9930 (SecurityFocus) |
°ü·Ã URL |
11412 (ISS) |
|