Ãë¾àÁ¡ID |
22297 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache HTTP ¼¹öÀÇ ¹è³ÊÁ¤º¸¿¡ µû¸£¸é, ¼¹ö´Â 'mod_proxy' ¸ðµâ »ó¿¡ Content-Length ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache HTTP ¼¹ö 1.3.26¿¡¼ 1.3.31±îÁöÀÇ ¹öÀü¿¡´Â 'mod_proxy' ¸ðµâ¿¡¼ 'Cotent-Length' Çì´õ¿¡ ¿Ã¹Ù¸£Áö ¾ÊÀº À½¼ö(negative)ÀÇ »ç¿ëÀÚ Á¤ÀÇ °ªÀÌ »ç¿ëµÇ¾î ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ À½¼öÀÇ 'Content-Length' °ªÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ¼¹ö »ó¿¡¼ ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í ÀÌ·Î ÀÎÇÏ¿© ¼ºñ½º °ÅºÎ ¶Ç´Â ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0276.html http://www.osvdb.org/6839
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache Software Foundation, Apache HTTP Server 1.3.26 - 1.3.31 Debian Linux 3.0 Gentoo Linux ¸ðµç ¹öÀü HP-UX 11.04, ¸ðµç ¹öÀü IBM HTTP Server 1.3.26, 1.3.28 Mandrake Linux 10.0, 9.1, 9.2, Corporate Server 2.1 OpenPKG 1.3, 2.0, CURRENT Red Hat Advanced Workstation 2.1AS Red Hat Enterprise Linux 2.1AS, 2.1ES, 2.1WS Solaris 8, 9 ¸ðµç ¿î¿µÃ¼Á¦ÀÇ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian º¸¾È ±Ç°í¹® DSA-525-1 ¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.26-0woody5 ¶Ç´Â ±× ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-525
Gentoo Linux SecurityÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux º¸¾È ±Ç°í¹® GLSA 200406-16 ¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ¹öÀü(1.3.31-r2 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200406-16.xml
HP-UX11.04ÀÇ °æ¿ì: http://www.itrc.hp.com/ ¿¡¼ ÀûÀýÇÑ ÆÐÄ¡¸¦ ´Ù¿î·Îµå ÇÑ´Ù. ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© HPSBUX01057¿¡ ¸Âµµ·Ï ÀûÀýÇÑ Apache ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://en.securitylab.ru/notification/237606.php
Mandrake LinuxÀÇ °æ¿ì, |
°ü·Ã URL |
CVE-2004-0492 (CVE) |
°ü·Ã URL |
10508 (SecurityFocus) |
°ü·Ã URL |
16387 (ISS) |
|