English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22298
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache HTTP ¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é, ¼­¹ö´Â 'mod_include' ¸ðµâ »ó¿¡ ·ÎÄà ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Apache HTTP ¼­¹ö ¹öÀü 1.3.x ¿¡´Â 'mod_include' ¸ðµâÀÇ get_tag() ÇÔ¼ö¿¡¼­ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·Â 'tag' ¹®ÀÚ¿­À» º¹»çÇϱâ Àü¿¡ ¿Ã¹Ù¸¥ ±æÀÌ °Ë»ç¸¦ ¼öÇàÇÏÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ·ÎÄà °ø°ÝÀÚµéÀº 'mod_include' ¸ðµâÀÇ 'get_tag' ÇÔ¼ö¿¡ Àß Á¶ÀÛµÈ URLÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í Apache ¼­¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ嵵 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2004/Oct/1011783.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache Software Foundation, Apache HTTP Server 1.3.33 ÀÌÀüÀÇ 1.3.x
Linux ¸ðµç ¹öÀü
Unix ¸ðµç ¹öÀü
ÇØ°áÃ¥ Gentoo Linux: GLSA 200411-03¸¦ Âü°íÇÏ¿© 1.3.32-r1 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù.
http://www.gentoo.org/security/en/glsa/glsa-200411-03.xml

Mandrake Linux: MDKSA-2004:134¸¦ Âü°íÇÏ¿© ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù.
http://www.mandriva.com/en/support/security/advisories/

Debian GNU/Linux 3.0 (alias woody): DSA-594-1¸¦ Âü°íÇÏ¿© 1.3.26-0woody6 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù.
http://www.debian.org/security/2004/dsa-594

HP-UX 11.00, 11.11, 11.22, 11.20: ´ÙÀ½ ÈÞ·¿ ÆÐÄ¿µå»ç º¸¾È °Ô½Ã¹° HPSBUX01098À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00900681

Solaris : ½Ã½ºÅÛ¿¡ ¸Â°Ô ÆÐÄ¡ÇØ¾ß ÇÑ´Ù.
https://support.oracle.com/

Solaris 8_sparc : 116973-03
Solaris 9_sparc : 113146-07
Solaris 9_x86 : 114145-06

Red Hat Linux Stronghold: RHSA-2005:816-10¸¦ Âü°íÇÏ¿© ÆÐÄ¡ÇØ¾ß ÇÑ´Ù.
https://rhn.redhat.com/errata/RHSA-2005-816.html

±× ¿ÜÀÇ ½Ã½ºÅÛ:
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/ ¿¡¼­ ÃֽйöÀüÀÇ Apache HTTP Server·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù.
°ü·Ã URL CVE-2004-0940 (CVE)
°ü·Ã URL 11471 (SecurityFocus)
°ü·Ã URL 17785 (ISS)