English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22269
À§Çèµµ 40
Æ÷Æ® 3128,8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Webproxy
»ó¼¼¼³¸í ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â NTLM ÀÎÁõ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á À¥ ÇÁ·Ï½Ã ¼­¹öÀÌ´Ù. Squid Web Proxy Cache 2.5-STABLE ±×¸®°í 3-PRE ¹öÀüµéÀº NTLM ÀÎÁõ Á¤º¸µéÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼­ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ °áÇÔÀº »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» º¹»çÇÒ ¶§ ÀûÀýÇÏ°Ô ¹öÆÛ °æ°èÄ¡¸¦ °Ë»çÇÏÁö ¸øÇÏ´Â ¾îÇø®ÄÉÀÌ¼Ç »óÀÇ ¿À·ù°¡ ¿øÀÎÀÌ µÈ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Squid Proxy°¡ NTLM ÀÎÁõ µµ¿ì¹Ì(helper)¸¦ »ç¿ëÇÏ´Â °ÍÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ» °æ¿ì, ´ë»ó ½Ã½ºÅÛÀ» ÇØÅ·ÇÒ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ¾ÆÁÖ ±ä ÆÐ½º¿öµå ("pass" º¯¼ö)¸¦ º¸³» ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0191.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
National Science Foundation, Squid Web Proxy Cache 2.5-STABLE
National Science Foundation, Squid Web Proxy Cache 3-PRE
Linux Any version
Unix Any version
ÇØ°áÃ¥ Squid Web Proxy Cache 2.5-STABLEÀÇ °æ¿ì:
´ÙÀ½ °ø½Ä Squid-2.5 Patches »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE5-ntlm_auth_overflow.patch

Red Hat LinuxÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2004:242-06À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
https://rhn.redhat.com/errata/RHSA-2004-242.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SuSE-SA:2004:016À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_16_squid.html

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:059¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/


Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200406-13À» ÂüÁ¶ÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.5-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0541 (CVE)
°ü·Ã URL 10500 (SecurityFocus)
°ü·Ã URL 16360 (ISS)