Ãë¾àÁ¡ID |
22273 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache À¥¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â ¾×¼¼½º ·ê(Access Rule) ¿ìȸ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache À¥¼¹ö´Â Apache Software Foundation¿¡ ÀÇÇØ À¯Áöº¸¼ö µÇ´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¸Å¿ì ÀαâÀÖ´Â À¥¼¹öÀÌ´Ù. ºò ¿£µð¾È(big-endian) 64ºñÆ® Ç÷§Æû »ó¿¡¼ Apache À¥ ¼¹ö 1.3.29 ¹öÀü°ú ±× ÀÌÀü ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ Á¤ÇØÁø ¾×¼¼½º Á¦ÇÑÀ» ¿ìȸÇϵµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â Çã¿ë(Allow) ¶Ç´Â °ÅºÎ(Deny) ·ê¿¡¼ ³Ý¸¶½ºÅ©(Netmask) ¾øÀÌ IP ÁÖ¼Ò¸¦ »ç¿ëÇÒ °æ¿ì, 'mod_access' ¸ðµâÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ÀûÀýÇÑ ·êÀ» ¸ÅĪÇÏÁö ¸øÇϱ⠶§¹®¿¡ ¹ß»ýÇÑ´Ù. ÀÌ Ãë¾àÁ¡À» ¼º°øÀ¸·Î µµ¿ëÇϸé, ¿ø°ÝÁö °ø°ÝÀڵ鿡°Ô´Â ºñÀΰ¡µÈ ÆÄÀÏ ¹× µð·ºÅ丮¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» Çã¿ëÇÏ´Â ¹Ý¸é, Á¤´çÇÑ »ç¿ëÀڵ鿡°Ô´Â ¾×¼¼½º ±ÇÇÑÀ» °ÅºÎÇÏ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://securitytracker.com/alerts/2004/Mar/1009338.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 1.3.29 ÀÌÇÏ Gentoo Linux Any version Mandrake Linux 10.0, 9.2 Mandrake Linux Corporate Server 1.0.1, 2.1 Mandrake Multi Network Firewall 8.2 OpenBSD 3.3, OpenBSD 3.4 Slackware Linux 8.1, 9.0, 9.1, current Trustix Secure Linux 1.5 Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Apache Software FoundationÀÇ ´Ù¿î·Îµå »çÀÌÆ®, http://httpd.apache.org ¿¡¼ Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(1.3.30-dev ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
±âŸ: º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0993 (CVE) |
°ü·Ã URL |
9829 (SecurityFocus) |
°ü·Ã URL |
15422 (ISS) |
|