English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210220
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpdÀÇ ¹öÀüÀÌ 2.4.54 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼­ 2.4.54 ±Ç°í¿¡¼­ ¾ð±ÞÇÑ ¿©·¯ °¡Áö Ãë¾à¼ºÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- mod_proxy_ajp: Apache HTTP ServerÀÇ mod_proxy_ajp HTTP ¿äû Çؼ® ºÒÀÏÄ¡ ('HTTP Request Smuggling') Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¿äûÀ» Àü´ÞÇÏ´Â AJP ¼­¹ö¿¡ ¿äûÀ» ¸ô·¡ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦´Â Apache HTTP Server Apache HTTP Server 2.4 ¹öÀü 2.4.53 ¹× ÀÌÀü ¹öÀü¿¡ ¿µÇâÀ» ÁÝ´Ï´Ù (CVE-2022-26377)

- mod_isapi¿¡¼­ ¹üÀ§¸¦ ¹þ¾î³­ Àбâ: mod_isapi ¸ðµâ·Î ¿äûÀ» ó¸®Çϵµ·Ï ±¸¼ºµÈ °æ¿ì WindowsÀÇ Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀº ¹üÀ§¸¦ ¹þ¾î³­ Àб⸦ ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-28330)

- ap_rwrite()¸¦ ÅëÇØ ¹üÀ§¸¦ ¹þ¾î³­ Àбâ: °ø°ÝÀÚ°¡ mod_luaser:puts() ÇÔ¼ö¿Í °°ÀÌ ap_rwrite() ¶Ç´Â ap_rputs()¸¦ »ç¿ëÇÏ¿© ¼­¹ö°¡ ¸Å¿ì Å« ÀÔ·ÂÀ» ¹Ý¿µÇϵµ·Ï ÇÒ ¼ö ÀÖ´Â °æ¿ì Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀÇ ap_rwrite() ÇÔ¼ö´Â ÀǵµÇÏÁö ¾ÊÀº ¸Þ¸ð¸®¸¦ ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù.(CVE-2022-28614)

- ap_strcmp_match()¿¡¼­ ¹üÀ§¸¦ ¹þ¾î³­ Àбâ: Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀº ¸Å¿ì Å« ÀÔ·Â ¹öÆÛ¸¦ Á¦°øÇÒ ¶§ ap_strcmp_match()ÀÇ ¹üÀ§¸¦ ¹þ¾î³­ Àб⠶§¹®¿¡ Á¤º¸°¡ Ãæµ¹Çϰųª ³ëÃâµÉ ¼ö ÀÖ½À´Ï´Ù. ¼­¹ö¿Í ÇÔ²² ¹èÆ÷µÈ ¾î¶² Äڵ嵵 ÀÌ·¯ÇÑ È£Ãâ¿¡ °­Á¦ÇÒ ¼ö ¾øÁö¸¸, ap_strcmp_match()¸¦ »ç¿ëÇϴ Ÿ»ç ¸ðµâÀ̳ª ·ç¾Æ ½ºÅ©¸³Æ®°¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-28615)

- mod_luar:parsebody:ÀÇ ¼­ºñ½º °ÅºÎ: Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀü¿¡¼­´Â r:parsebody(0)¸¦ È£ÃâÇÏ´Â ·ç¾Æ ½ºÅ©¸³Æ®¿¡ ´ëÇØ ¾ÇÀÇÀûÀÎ ¿äû¿¡ ÀÔ·Â Å©±â ±âº» Á¦ÇÑÀÌ ¾øÀ¸¹Ç·Î ¼­ºñ½º °ÅºÎ¸¦ ¹ß»ý½Ãų ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-29404)

- ¼­ºñ½º °ÅºÎ mod_sed: ¾ÆÆÄÄ¡ HTTP ¼­¹ö 2.4.53ÀÌ mod_sed¿¡ ´ëÇÑ ÀÔ·ÂÀÌ ¸Å¿ì Ŭ ¼ö ÀÖ´Â ÄÁÅؽºÆ®¿¡¼­ mod_sed·Î º¯È¯À» ¼öÇàÇϵµ·Ï ±¸¼ºµÈ´Ù¸é mod_sed´Â °úµµÇÏ°Ô Å« ¸Þ¸ð¸®¸¦ ÇÒ´çÇÏ°í Áß´Ü ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-30522)

- À¥ ¼ÒÄÏÀ» »ç¿ëÇÏ¿© mod_luaÀÇ Á¤º¸ ³ëÃâ: ¾ÆÆÄÄ¡ HTTP ¼­¹ö 2.4.53 ÀÌÀü ¹öÀüÀº ¹öÆÛ¿¡ ÇÒ´çµÈ ½ºÅ丮ÁöÀÇ ³¡À» °¡¸®Å°´Â r:wsread()¸¦ È£ÃâÇϸé ÀÀ¿ë ÇÁ·Î±×·¥ ±æÀ̸¦ ¹ÝȯÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-30556)

- X-Forwarded-mod_proxyÀÇ È© ¹ÙÀÌ È© ¸ÞÄ¿´ÏÁò¿¡ ÀÇÇØ »èÁ¦µÇ´Â °æ¿ì: Apache HTTP ¼­¹ö 2.4.53 ÀÌÀü ¹öÀüÀº Ŭ¶óÀ̾ðÆ® Ãø ¿¬°á Çì´õ È© ¹ÙÀÌ È© ¸ÞÄ¿´ÏÁò¿¡ µû¶ó X-Forwarded-* Çì´õ¸¦ ¿øº» ¼­¹ö·Î º¸³»Áö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ¼­¹ö/¾ÖÇø®ÄÉÀ̼ǿ¡¼­ IP ±â¹Ý ÀÎÁõÀ» ¹ÙÀÌÆнºÇÏ´Â µ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù.(CVE-2022-31813)

* Âü°í »çÀÌÆ®:

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 2.4.54 ÀÌÀü 2.4.x ¹öÀü
Any operating system Any version
ÇØ°áÃ¥ Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.54 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2022-26377,CVE-2022-28330,CVE-2022-28614,CVE-2022-28615,CVE-2022-29404,CVE-2022-30522,CVE-2022-30556,CVE-2022-31813 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)