English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22264
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache À¥ ¼­¹öÀÇ ¹è³ÊÁ¤º¸¿¡ µû¸£¸é, ¼­¹ö´Â ¿¡·¯ ·Î±× Escape Sequence Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
ÀϹÝÀûÀ¸·Î "Escape Sequence"´Â ÇÁ¸°Åͳª ¸ð´ÏÅÍ¿Í °°Àº Display ÀåÄ¡µéÀÇ È­¸é ¼Ó¼ºµéÀ» Á¦¾îÇϱâ À§ÇØ »ç¿ëµÇ´Â, ASCII ESC(Escape:0x1B)¹®ÀÚ·Î ½ÃÀÛÇÏ´Â ¹®ÀÚ¿­ ¹­À½À¸·Î¼­, µÚ¿¡ Ư¼öÇÑ ¹®ÀÚ¿­ÀÌ Ãß°¡ÀûÀ¸·Î µû¸£°Ô µÈ´Ù. ÀϺΠApache ¼­¹ö ¹öÀüÀº ¿¡·¯ ·Î±×·ÎºÎÅÍ escape sequence¸¦ ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿©, escape sequenceµéÀÌ Apache ·Î±× ÆÄÀϵ鿡 »ðÀԵǴ °ÍÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚµéÀÌ escape sequence °ü·Ã Ãë¾àÁ¡µéÀ» ¾È°í ÀÖ´Â ¸¹Àº Å͹̳Π¿¡¹Ä·¹ÀÌÅÍ ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö(Terminal Emulator software package)¸¦ »ç¿ëÇÏ¿© ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇØ º¸´Ù ½±°Ô °ø°ÝÀ» ¼öÇàÇϵµ·Ï µµ¿ÍÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¸é ¼­ºñ½º °ÅºÎ(Denial of Service) °ø°Ý, ÆÄÀÏ º¯°æ, µ¥ÀÌÅÍ º¯°æ, ÀÓÀÇÀÇ ¸í·É ½ÇÇà µîÀÇ °ø°ÝÀÌ °¡´ÉÇÏ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache Software Foundation Apache HTTP Server 1.3.x
Apache Software Foundation Apache HTTP Server 2.0.x
Red Hat Linux 7.1, 7.2, 7.3, 8.0, 9
Mandrake Linux 10.0, 9.1, 9.2, Corporate Server 2.1, Multi Network Firewall 8.2
Slackware Linux 8.1, 9.0, 9.1, current
Trustix: Trustix Secure Linux 1.5, 2.0, 2.1
Turbolinux 10 Desktop
Conectiva Linux 8.0, 9.0
IRIX 2.2.1, 2.3
Windows, Linux, Unix : Any version
ÇØ°áÃ¥ Apache HTTP Server 1.3.x ±×¸®°í 2.0.xÀÇ °æ¿ì:
´ÙÀ½ Apache Software FoundationÀÇ ´Ù¿î·Îµå »çÀÌÆ®, http://httpd.apache.org ¸¦ ÂüÁ¶ÇÏ¿© Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(1.3.31 ÀÌ»ó ¶Ç´Â 2.0.49 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:

RedHat ¸®´ª½º 7.x and 8.0, 9ÀÇ °æ¿ì:
´ÙÀ½ Red HatÀÇ Security Advisory RHSA-2003:139-07 ¿Í RHSA-2003:243-07¸¦ ÂüÁ¶ÇÏ¿© Apache(httpd) ÆÐŰÁöÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2003-243.html
https://rhn.redhat.com/errata/RHSA-2003-139.html

Mandrake ¸®´ª½ºÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoftÀÇ Security Advisory MDKSA-2004:046¸¦ ÂüÁ¶ÇÏ¿© Apache ÆÐŰÁöÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/


±âŸ:
ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0020 (CVE)
°ü·Ã URL 9930 (SecurityFocus)
°ü·Ã URL 11412 (ISS)