Ãë¾àÁ¡ID |
22298 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache HTTP ¼¹öÀÇ ¹öÀü¿¡ µû¸£¸é, ¼¹ö´Â 'mod_include' ¸ðµâ »ó¿¡ ·ÎÄà ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache HTTP ¼¹ö ¹öÀü 1.3.x ¿¡´Â 'mod_include' ¸ðµâÀÇ get_tag() ÇÔ¼ö¿¡¼ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·Â 'tag' ¹®ÀÚ¿À» º¹»çÇϱâ Àü¿¡ ¿Ã¹Ù¸¥ ±æÀÌ °Ë»ç¸¦ ¼öÇàÇÏÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ·ÎÄà °ø°ÝÀÚµéÀº 'mod_include' ¸ðµâÀÇ 'get_tag' ÇÔ¼ö¿¡ Àß Á¶ÀÛµÈ URLÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ¹öÆÛ ¿À¹öÇ÷ο츦 ¹ß»ý½Ã۰í Apache ¼¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ嵵 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Oct/1011783.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache Software Foundation, Apache HTTP Server 1.3.33 ÀÌÀüÀÇ 1.3.x Linux ¸ðµç ¹öÀü Unix ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Gentoo Linux: GLSA 200411-03¸¦ Âü°íÇÏ¿© 1.3.32-r1 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù. http://www.gentoo.org/security/en/glsa/glsa-200411-03.xml
Mandrake Linux: MDKSA-2004:134¸¦ Âü°íÇÏ¿© ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù. http://www.mandriva.com/en/support/security/advisories/
Debian GNU/Linux 3.0 (alias woody): DSA-594-1¸¦ Âü°íÇÏ¿© 1.3.26-0woody6 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù. http://www.debian.org/security/2004/dsa-594
HP-UX 11.00, 11.11, 11.22, 11.20: ´ÙÀ½ ÈÞ·¿ ÆÐÄ¿µå»ç º¸¾È °Ô½Ã¹° HPSBUX01098À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00900681
Solaris : ½Ã½ºÅÛ¿¡ ¸Â°Ô ÆÐÄ¡ÇØ¾ß ÇÑ´Ù. https://support.oracle.com/
Solaris 8_sparc : 116973-03 Solaris 9_sparc : 113146-07 Solaris 9_x86 : 114145-06
Red Hat Linux Stronghold: RHSA-2005:816-10¸¦ Âü°íÇÏ¿© ÆÐÄ¡ÇØ¾ß ÇÑ´Ù. https://rhn.redhat.com/errata/RHSA-2005-816.html
±× ¿ÜÀÇ ½Ã½ºÅÛ: Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/ ¿¡¼ ÃֽйöÀüÀÇ Apache HTTP Server·Î ¾÷±×·¹À̵å ÇØ¾ßÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-0940 (CVE) |
°ü·Ã URL |
11471 (SecurityFocus) |
°ü·Ã URL |
17785 (ISS) |
|