Ãë¾àÁ¡ID |
210268 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀÌ 2.4.58 ÀÌÀüÀÔ´Ï´Ù. µû¶ó¼ 2.4.58 ±Ç°í¿¡ ¾ð±ÞµÈ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- RST Ç÷¡±×°¡ ÀÖ´Â ÆÐŶÀÌ HTTP/2 ½ºÆ®¸²À» Àç¼³Á¤ÇÑ ÈÄ Áö¿¬µÈ ¸Þ¸ð¸® ÇÒ´ç ÇØÁ¦·Î ÀÎÇØ ¸Þ¸ð¸® °í°¥ Á¶°ÇÀÌ »ý¼ºµË´Ï´Ù. RST Ç÷¡±×°¡ ó¸®µÈ Á÷ÈÄ¿¡ ¸Þ¸ð¸®°¡ ÇØÁ¦µÇ´Â °ÍÀÌ ¾Æ´Ï¶ó ¿¬°áÀÌ ´ÝÈù ÈÄ¿¡¸¸ ¸Þ¸ð¸®°¡ ÇØÁ¦µÇ¹Ç·Î °ø°ÝÀÚ´Â ¿¬°áÀ» ´ÝÁö ¾Ê°íµµ »õ·Î¿î ¿äûÀ» º¸³»°í RST ÆÐŶÀ¸·Î Ç÷¯½ÃÇÔÀ¸·Î½á ¸Þ¸ð¸® ¼Òºñ¸¦ Å©°Ô ´Ã¸± ¼ö ÀÖ½À´Ï´Ù.¸®Æ÷ÅÍ°¡ ÀÚü Å×½ºÆ® Ŭ¶óÀ̾ðÆ®¸¦ »ç¿ëÇÏ¿© CVE-2023-44487(HTTP/2 Rapid Reset Exploit)À» Å×½ºÆ®ÇÏ´Â µ¿¾È ¹ß°ßÇÑ °ÍÀÔ´Ï´Ù. "ÀϹÝÀûÀÎ" HTTP/2 »ç¿ë Áß¿¡´Â ÀÌ ¹ö±×°¡ ¹ß»ýÇÒ È®·üÀÌ ¸Å¿ì ³·½À´Ï´Ù. ¿¬°áÀÌ ´ÝÈ÷°Å³ª ½Ã°£ÀÌ ÃÊ°úµÇ±â Àü¿¡´Â º¸°üµÈ ¸Þ¸ð¸®°¡ ´«¿¡ ¶çÁö ¾Ê½À´Ï´Ù. »ç¿ëÀÚ´Â ¹®Á¦¸¦ ÇØ°áÇÏ´Â ¹öÀü 2.4.58·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. (CVE-2023-45802)
* Âü°í »çÀÌÆ®: https://httpd.apache.org/security/vulnerabilities_24.html https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/ https://security.netapp.com/advisory/ntap-20231027-0011/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 2.4.58 ÀÌÀü ¸ðµç ¹öÀü Any operating system Any version |
ÇØ°áÃ¥ |
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.58 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2023-45802 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|