Ãë¾àÁ¡ID |
22280 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
Apache HTTP ¼¹ö 2.0¿¡¼ 2.0.50 »çÀÌÀÇ ¹öÀüµé¿¡´Â ´ÙÁßÀÇ ¿ø°Ý ¹× ·ÎÄà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. 2.0.51 ÀÌÀüÀÇ ¸ðµç Apache 2.0 ¹öÀüµéÀº ´ÙÀ½ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸°í µÇ¾ú´Ù:
- .htaccess ȤÀº httpd.conf ±¸¼º ÆÄÀÏ¿¡ Àִ ȯ°æ º¯¼öµéÀ» È®ÀåÇÒ ¶§ ·ÎÄà °ø°ÝÀÚ¿¡ ÀÇÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ (CVE-2004-0747). - mod_ssl ÀÎÁõ ¸ðµâÀÌ ¿øÀÎÀÌ µÇ´Â ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0748). - Speculative ¸ðµå·Î µ¿ÀÛÇÒ ¶§ mod_sslÀÇ ÀÎÁõ ¸ðµâ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0751). - apr_util ¶óÀ̺귯¸®¿¡ ÀÖ´Â IPv6 URI ÇØ¼® ·çƾµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0786). - mod_davÀÇ distributed authoring and versioning (DAV) ¸ðµâ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0809).
°ø°ÝÀÚ´Â ÀÌ °áÇÔµéÀº ÀÌ¿ëÇÏ¿© httpd ÇÁ·Î¼¼½º¸¦ Å©·¡½¬(Crash) ½ÃŰ°Å³ª ½ÉÁö¾î ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Apache À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 2.0¿¡¼ 2.0.50 ±îÁöÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Apache HTTP Server ProjectÀÇ À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(2.0.51-dev ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Red Hat LinuxÀÇ °æ¿ì: Upgrade to the latest httpd package, as listed in Red Hat Security Advisory RHSA-2004:463-09 at https://rhn.redhat.com/errata/RHSA-2004-463.html
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SUSE-SA:2004:032¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ httpd ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_32_apache2.html
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:096À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ apache2 ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200409-21À» ÂüÁ¶ÇÏ¿© apacheÀÇ °¡Àå ÃֽйöÀü(2.0.51, < 2.0 ȤÀº ÀÌÈÄ) ȤÀº mod_davÀÇ °¡Àå ÃֽйöÀü(1.0.3-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml
±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
CVE-2004-0747,CVE-2004-0748,CVE-2004-0751,CVE-2004-0786,CVE-2004-0809 (CVE) |
°ü·Ã URL |
11094,11154,11182,11185,11187 (SecurityFocus) |
°ü·Ã URL |
17200,17382,17384,17273,17366 (ISS) |
|