English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22273
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache À¥¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â ¾×¼¼½º ·ê(Access Rule) ¿ìȸ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Apache À¥¼­¹ö´Â Apache Software Foundation¿¡ ÀÇÇØ À¯Áöº¸¼ö µÇ´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¸Å¿ì ÀαâÀÖ´Â À¥¼­¹öÀÌ´Ù. ºò ¿£µð¾È(big-endian) 64ºñÆ® Ç÷§Æû »ó¿¡¼­ Apache À¥ ¼­¹ö 1.3.29 ¹öÀü°ú ±× ÀÌÀü ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ Á¤ÇØÁø ¾×¼¼½º Á¦ÇÑÀ» ¿ìȸÇϵµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ´Â Çã¿ë(Allow) ¶Ç´Â °ÅºÎ(Deny) ·ê¿¡¼­ ³Ý¸¶½ºÅ©(Netmask) ¾øÀÌ IP ÁÖ¼Ò¸¦ »ç¿ëÇÒ °æ¿ì, 'mod_access' ¸ðµâÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ÀûÀýÇÑ ·êÀ» ¸ÅĪÇÏÁö ¸øÇϱ⠶§¹®¿¡ ¹ß»ýÇÑ´Ù. ÀÌ Ãë¾àÁ¡À» ¼º°øÀ¸·Î µµ¿ëÇϸé, ¿ø°ÝÁö °ø°ÝÀڵ鿡°Ô´Â ºñÀΰ¡µÈ ÆÄÀÏ ¹× µð·ºÅ丮¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» Çã¿ëÇÏ´Â ¹Ý¸é, Á¤´çÇÑ »ç¿ëÀڵ鿡°Ô´Â ¾×¼¼½º ±ÇÇÑÀ» °ÅºÎÇÏ´Â °á°ú¸¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2004/Mar/1009338.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 1.3.29 ÀÌÇÏ
Gentoo Linux Any version
Mandrake Linux 10.0, 9.2
Mandrake Linux Corporate Server 1.0.1, 2.1
Mandrake Multi Network Firewall 8.2
OpenBSD 3.3, OpenBSD 3.4
Slackware Linux 8.1, 9.0, 9.1, current
Trustix Secure Linux 1.5
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ Apache Software FoundationÀÇ ´Ù¿î·Îµå »çÀÌÆ®, http://httpd.apache.org ¿¡¼­ Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(1.3.30-dev ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0993 (CVE)
°ü·Ã URL 9829 (SecurityFocus)
°ü·Ã URL 15422 (ISS)