English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22267
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache HTTP À¥ ¼­¹ö´Â mode_proxy ¸ðµâ »óÀÇ Èü(Heap) ±â¹Ý ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache ¹öÀü 1.3.26°ú 1.3.31 »çÀÌÀÇ À¥ ¼­¹öµé¿¡´Â ¿ø°ÝÁö °ø°ÝÀڵ鿡 ÀÇÇØ ¼­ºñ½º °ÅºÎ °ø°Ý ¶Ç´Â ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡Àº À¥ ¼­¹ö°¡ ¿Ã¹Ù¸£°Ô Content-Length Çʵ带 °Ë»çÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº mod_proxy¸¦ ÅëÇØ À߸øµÈ Content-Length °ªÀ» ¹ÝȯÇÏ´Â ¾ÇÀÇÀûÀÎ ¼­¹ö¿¡ ¿¬°áÇÏ¿© ÇØ´ç ¿ø°ÝÁö Apache À¥ ¼­¹ö°¡ Àß Á¶ÀÛµÈ À½¼öÀÇ Content-Length °ªÀ» Àü´Þ¹Þµµ·Ï ÇÔÀ¸·Î½á, ¼­ºñ½º °ÅºÎ ¹× ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ ÄÚµå ½ÇÇ൵ °¡´ÉÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ¸¸¾à Apache ¼­¹ö°¡ mod_proxy ¸ðµâÀ» ·ÎµåÇÏÁö ¾Ê¾Ò´Ù¸é ÀÌ Ãë¾àÁ¡Àº ¹«½ÃÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=apache-httpd-dev&m=108687304202140
http://www.guninski.com/modproxy1.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 1.3.26 ~ 1.3.31
Debian Linux 3.0
Gentoo Linux Any version
OpenPKG 1.3, 2.0, CURRENT
Red Hat Advanced Workstation 2.1AS, Enterprise Linux 2.1AS, 2.1ES, 2.1WS
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Red Hat Linux ÀÇ °æ¿ì:
´ÙÀ½ÀÇ Red Hat º¸¾È ±Ç°í¹® RHSA-2004:245-14 ¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-245.html

Debian GNU/Linux 3.0 (woody) ÀÇ °æ¿ì:
´ÙÀ½ÀÇ Debian º¸¾È ±Ç°í¹® DSA-525-1¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.26-0woody5 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-525

Gentoo Linux Security ÀÇ °æ¿ì:
´ÙÀ½ÀÇ Gentoo Linux º¸¾È ±Ç°í¹® GLSA 200406-16¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.31-r2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200406-16.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-0492 (CVE)
°ü·Ã URL 10508 (SecurityFocus)
°ü·Ã URL 16387 (ISS)