English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22297
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache HTTP ¼­¹öÀÇ ¹è³ÊÁ¤º¸¿¡ µû¸£¸é, ¼­¹ö´Â 'mod_proxy' ¸ðµâ »ó¿¡ Content-Length ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache HTTP ¼­¹ö 1.3.26¿¡¼­ 1.3.31±îÁöÀÇ ¹öÀü¿¡´Â 'mod_proxy' ¸ðµâ¿¡¼­ 'Cotent-Length' Çì´õ¿¡ ¿Ã¹Ù¸£Áö ¾ÊÀº À½¼ö(negative)ÀÇ »ç¿ëÀÚ Á¤ÀÇ °ªÀÌ »ç¿ëµÇ¾î ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ À½¼öÀÇ 'Content-Length' °ªÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ¼­¹ö »ó¿¡¼­ ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í ÀÌ·Î ÀÎÇÏ¿© ¼­ºñ½º °ÅºÎ ¶Ç´Â ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0276.html
http://www.osvdb.org/6839

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache Software Foundation, Apache HTTP Server 1.3.26 - 1.3.31
Debian Linux 3.0
Gentoo Linux ¸ðµç ¹öÀü
HP-UX 11.04, ¸ðµç ¹öÀü
IBM HTTP Server 1.3.26, 1.3.28
Mandrake Linux 10.0, 9.1, 9.2, Corporate Server 2.1
OpenPKG 1.3, 2.0, CURRENT
Red Hat Advanced Workstation 2.1AS
Red Hat Enterprise Linux 2.1AS, 2.1ES, 2.1WS
Solaris 8, 9
¸ðµç ¿î¿µÃ¼Á¦ÀÇ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian º¸¾È ±Ç°í¹® DSA-525-1 ¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.26-0woody5 ¶Ç´Â ±× ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-525

Gentoo Linux SecurityÀÇ °æ¿ì:
´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¹® GLSA 200406-16 ¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ¹öÀü(1.3.31-r2 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.gentoo.org/security/en/glsa/glsa-200406-16.xml

HP-UX11.04ÀÇ °æ¿ì: http://www.itrc.hp.com/ ¿¡¼­ ÀûÀýÇÑ ÆÐÄ¡¸¦ ´Ù¿î·Îµå ÇÑ´Ù.
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© HPSBUX01057¿¡ ¸Âµµ·Ï ÀûÀýÇÑ Apache ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://en.securitylab.ru/notification/237606.php

Mandrake LinuxÀÇ °æ¿ì,
°ü·Ã URL CVE-2004-0492 (CVE)
°ü·Ã URL 10508 (SecurityFocus)
°ü·Ã URL 16387 (ISS)