Ãë¾àÁ¡ID |
210220 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpdÀÇ ¹öÀüÀÌ 2.4.54 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼ 2.4.54 ±Ç°í¿¡¼ ¾ð±ÞÇÑ ¿©·¯ °¡Áö Ãë¾à¼ºÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- mod_proxy_ajp: Apache HTTP ServerÀÇ mod_proxy_ajp HTTP ¿äû Çؼ® ºÒÀÏÄ¡ ('HTTP Request Smuggling') Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¿äûÀ» Àü´ÞÇÏ´Â AJP ¼¹ö¿¡ ¿äûÀ» ¸ô·¡ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦´Â Apache HTTP Server Apache HTTP Server 2.4 ¹öÀü 2.4.53 ¹× ÀÌÀü ¹öÀü¿¡ ¿µÇâÀ» ÁÝ´Ï´Ù (CVE-2022-26377)
- mod_isapi¿¡¼ ¹üÀ§¸¦ ¹þ¾î³ Àбâ: mod_isapi ¸ðµâ·Î ¿äûÀ» ó¸®Çϵµ·Ï ±¸¼ºµÈ °æ¿ì WindowsÀÇ Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀº ¹üÀ§¸¦ ¹þ¾î³ Àб⸦ ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-28330)
- ap_rwrite()¸¦ ÅëÇØ ¹üÀ§¸¦ ¹þ¾î³ Àбâ: °ø°ÝÀÚ°¡ mod_luaser:puts() ÇÔ¼ö¿Í °°ÀÌ ap_rwrite() ¶Ç´Â ap_rputs()¸¦ »ç¿ëÇÏ¿© ¼¹ö°¡ ¸Å¿ì Å« ÀÔ·ÂÀ» ¹Ý¿µÇϵµ·Ï ÇÒ ¼ö ÀÖ´Â °æ¿ì Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀÇ ap_rwrite() ÇÔ¼ö´Â ÀǵµÇÏÁö ¾ÊÀº ¸Þ¸ð¸®¸¦ ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù.(CVE-2022-28614)
- ap_strcmp_match()¿¡¼ ¹üÀ§¸¦ ¹þ¾î³ Àбâ: Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀüÀº ¸Å¿ì Å« ÀÔ·Â ¹öÆÛ¸¦ Á¦°øÇÒ ¶§ ap_strcmp_match()ÀÇ ¹üÀ§¸¦ ¹þ¾î³ Àб⠶§¹®¿¡ Á¤º¸°¡ Ãæµ¹Çϰųª ³ëÃâµÉ ¼ö ÀÖ½À´Ï´Ù. ¼¹ö¿Í ÇÔ²² ¹èÆ÷µÈ ¾î¶² Äڵ嵵 ÀÌ·¯ÇÑ È£Ãâ¿¡ °Á¦ÇÒ ¼ö ¾øÁö¸¸, ap_strcmp_match()¸¦ »ç¿ëÇϴ Ÿ»ç ¸ðµâÀ̳ª ·ç¾Æ ½ºÅ©¸³Æ®°¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-28615)
- mod_luar:parsebody:ÀÇ ¼ºñ½º °ÅºÎ: Apache HTTP Server 2.4.53 ÀÌÀü ¹öÀü¿¡¼´Â r:parsebody(0)¸¦ È£ÃâÇÏ´Â ·ç¾Æ ½ºÅ©¸³Æ®¿¡ ´ëÇØ ¾ÇÀÇÀûÀÎ ¿äû¿¡ ÀÔ·Â Å©±â ±âº» Á¦ÇÑÀÌ ¾øÀ¸¹Ç·Î ¼ºñ½º °ÅºÎ¸¦ ¹ß»ý½Ãų ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-29404)
- ¼ºñ½º °ÅºÎ mod_sed: ¾ÆÆÄÄ¡ HTTP ¼¹ö 2.4.53ÀÌ mod_sed¿¡ ´ëÇÑ ÀÔ·ÂÀÌ ¸Å¿ì Ŭ ¼ö ÀÖ´Â ÄÁÅؽºÆ®¿¡¼ mod_sed·Î º¯È¯À» ¼öÇàÇϵµ·Ï ±¸¼ºµÈ´Ù¸é mod_sed´Â °úµµÇÏ°Ô Å« ¸Þ¸ð¸®¸¦ ÇÒ´çÇÏ°í Áß´Ü ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-30522)
- À¥ ¼ÒÄÏÀ» »ç¿ëÇÏ¿© mod_luaÀÇ Á¤º¸ ³ëÃâ: ¾ÆÆÄÄ¡ HTTP ¼¹ö 2.4.53 ÀÌÀü ¹öÀüÀº ¹öÆÛ¿¡ ÇÒ´çµÈ ½ºÅ丮ÁöÀÇ ³¡À» °¡¸®Å°´Â r:wsread()¸¦ È£ÃâÇϸé ÀÀ¿ë ÇÁ·Î±×·¥ ±æÀ̸¦ ¹ÝȯÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-30556)
- X-Forwarded-mod_proxyÀÇ È© ¹ÙÀÌ È© ¸ÞÄ¿´ÏÁò¿¡ ÀÇÇØ »èÁ¦µÇ´Â °æ¿ì: Apache HTTP ¼¹ö 2.4.53 ÀÌÀü ¹öÀüÀº Ŭ¶óÀ̾ðÆ® Ãø ¿¬°á Çì´õ È© ¹ÙÀÌ È© ¸ÞÄ¿´ÏÁò¿¡ µû¶ó X-Forwarded-* Çì´õ¸¦ ¿øº» ¼¹ö·Î º¸³»Áö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ¼¹ö/¾ÖÇø®ÄÉÀ̼ǿ¡¼ IP ±â¹Ý ÀÎÁõÀ» ¹ÙÀÌÆнºÇÏ´Â µ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù.(CVE-2022-31813)
* Âü°í »çÀÌÆ®:
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 2.4.54 ÀÌÀü 2.4.x ¹öÀü Any operating system Any version |
ÇØ°áÃ¥ |
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.54 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2022-26377,CVE-2022-28330,CVE-2022-28614,CVE-2022-28615,CVE-2022-29404,CVE-2022-30522,CVE-2022-30556,CVE-2022-31813 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|