English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22280
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Apache HTTP ¼­¹ö 2.0¿¡¼­ 2.0.50 »çÀÌÀÇ ¹öÀüµé¿¡´Â ´ÙÁßÀÇ ¿ø°Ý ¹× ·ÎÄà Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. 2.0.51 ÀÌÀüÀÇ ¸ðµç Apache 2.0 ¹öÀüµéÀº ´ÙÀ½ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸°í µÇ¾ú´Ù:

- .htaccess ȤÀº httpd.conf ±¸¼º ÆÄÀÏ¿¡ Àִ ȯ°æ º¯¼öµéÀ» È®ÀåÇÒ ¶§ ·ÎÄà °ø°ÝÀÚ¿¡ ÀÇÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ (CVE-2004-0747).
- mod_ssl ÀÎÁõ ¸ðµâÀÌ ¿øÀÎÀÌ µÇ´Â ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0748).
- Speculative ¸ðµå·Î µ¿ÀÛÇÒ ¶§ mod_sslÀÇ ÀÎÁõ ¸ðµâ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0751).
- apr_util ¶óÀ̺귯¸®¿¡ ÀÖ´Â IPv6 URI ÇØ¼® ·çƾµé¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0786).
- mod_davÀÇ distributed authoring and versioning (DAV) ¸ðµâ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÑ ¿ø°ÝÁö °ø°ÝÀÚ¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2004-0809).

°ø°ÝÀÚ´Â ÀÌ °áÇÔµéÀº ÀÌ¿ëÇÏ¿© httpd ÇÁ·Î¼¼½º¸¦ Å©·¡½¬(Crash) ½ÃŰ°Å³ª ½ÉÁö¾î ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Apache À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 2.0¿¡¼­ 2.0.50 ±îÁöÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Apache HTTP Server ProjectÀÇ À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(2.0.51-dev ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Red Hat LinuxÀÇ °æ¿ì:
Upgrade to the latest httpd package, as listed in Red Hat Security Advisory RHSA-2004:463-09 at https://rhn.redhat.com/errata/RHSA-2004-463.html

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE Security Announcement SUSE-SA:2004:032¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ httpd ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_32_apache2.html


Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:096À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ apache2 ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

Gentoo LinuxÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux Security Advisory GLSA 200409-21À» ÂüÁ¶ÇÏ¿© apacheÀÇ °¡Àå ÃֽйöÀü(2.0.51, < 2.0 ȤÀº ÀÌÈÄ) ȤÀº mod_davÀÇ °¡Àå ÃֽйöÀü(1.0.3-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù
http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml

±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0747,CVE-2004-0748,CVE-2004-0751,CVE-2004-0786,CVE-2004-0809 (CVE)
°ü·Ã URL 11094,11154,11182,11185,11187 (SecurityFocus)
°ü·Ã URL 17200,17382,17384,17273,17366 (ISS)