English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210268
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀÌ 2.4.58 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼­ 2.4.58 ±Ç°í¿¡ ¾ð±ÞµÈ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- RST Ç÷¡±×°¡ ÀÖ´Â ÆÐŶÀÌ HTTP/2 ½ºÆ®¸²À» Àç¼³Á¤ÇÑ ÈÄ Áö¿¬µÈ ¸Þ¸ð¸® ÇÒ´ç ÇØÁ¦·Î ÀÎÇØ ¸Þ¸ð¸® °í°¥ Á¶°ÇÀÌ »ý¼ºµË´Ï´Ù. RST Ç÷¡±×°¡ ó¸®µÈ Á÷ÈÄ¿¡ ¸Þ¸ð¸®°¡ ÇØÁ¦µÇ´Â °ÍÀÌ ¾Æ´Ï¶ó ¿¬°áÀÌ ´ÝÈù ÈÄ¿¡¸¸ ¸Þ¸ð¸®°¡ ÇØÁ¦µÇ¹Ç·Î °ø°ÝÀÚ´Â ¿¬°áÀ» ´ÝÁö ¾Ê°íµµ »õ·Î¿î ¿äûÀ» º¸³»°í RST ÆÐŶÀ¸·Î Ç÷¯½ÃÇÔÀ¸·Î½á ¸Þ¸ð¸® ¼Òºñ¸¦ Å©°Ô ´Ã¸± ¼ö ÀÖ½À´Ï´Ù.¸®Æ÷ÅÍ°¡ ÀÚü Å×½ºÆ® Ŭ¶óÀ̾ðÆ®¸¦ »ç¿ëÇÏ¿© CVE-2023-44487(HTTP/2 Rapid Reset Exploit)À» Å×½ºÆ®ÇÏ´Â µ¿¾È ¹ß°ßÇÑ °ÍÀÔ´Ï´Ù. "ÀϹÝÀûÀÎ" HTTP/2 »ç¿ë Áß¿¡´Â ÀÌ ¹ö±×°¡ ¹ß»ýÇÒ È®·üÀÌ ¸Å¿ì ³·½À´Ï´Ù. ¿¬°áÀÌ ´ÝÈ÷°Å³ª ½Ã°£ÀÌ ÃÊ°úµÇ±â Àü¿¡´Â º¸°üµÈ ¸Þ¸ð¸®°¡ ´«¿¡ ¶çÁö ¾Ê½À´Ï´Ù. »ç¿ëÀÚ´Â ¹®Á¦¸¦ ÇØ°áÇÏ´Â ¹öÀü 2.4.58·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. (CVE-2023-45802)

* Âü°í »çÀÌÆ®:
https://httpd.apache.org/security/vulnerabilities_24.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/
https://security.netapp.com/advisory/ntap-20231027-0011/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 2.4.58 ÀÌÀü ¸ðµç ¹öÀü
Any operating system Any version
ÇØ°áÃ¥ Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.58 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2023-45802 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)