| Ãë¾àÁ¡ID |
210293 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀÌ 2.4.67 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼ 2.4.67 ±Ç°í¹®¿¡¼ ¾ð±ÞµÈ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.
- Apache HTTP ServerÀÇ mod_proxy_ajp¿¡ Á¸ÀçÇÏ´Â Èü ±â¹Ý ¹öÆÛ ¿À¹öÇ÷Î(Heap-based Buffer Overflow) Ãë¾àÁ¡. mod_proxy_ajp°¡ ¾Ç¼º AJP ¼¹ö¿¡ ¿¬°áµÇ´Â °æ¿ì, ÇØ´ç AJP ¼¹ö´Â ¾ÇÀÇÀûÀÎ AJP ¸Þ½ÃÁö¸¦ mod_proxy_ajp·Î ´Ù½Ã Àü¼ÛÇÏ¿© Èü ±â¹Ý ¹öÆÛÀÇ ³¡À» ³Ñ¾î °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â 4¹ÙÀÌÆ®¸¦ ¾²µµ·Ï À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦´Â 2.4.66 ÀÌÇÏÀÇ Apache HTTP Server ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-28780) - HTTP/2 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â Apache HTTP Server¿¡ Á¸ÀçÇÏ´Â ÀÌÁß ÇØÁ¦(Double Free) ¹× ¿ø°Ý ÄÚµå ½ÇÇà(RCE) °¡´É¼º Ãë¾àÁ¡. ÀÌ ¹®Á¦´Â Apache HTTP Server 2.4.66 ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-23918) - Apache HTTP 2.4.66 ¹× ÀÌÀü ¹öÀüÀÇ ´Ù¾çÇÑ ¸ðµâ¿¡ Á¸ÀçÇÏ´Â ±ÇÇÑ »ó½Â ¹ö±×·Î ÀÎÇØ ·ÎÄà .htaccess ÀÛ¼ºÀÚ°¡ httpd »ç¿ëÀÚÀÇ ±ÇÇÑÀ¸·Î ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-24072) - OCSP ÀÀ´ä µ¥ÀÌÅ͸¦ ÅëÇÑ Apache HTTP Server mod_mdÀÇ Á¦ÇÑ ¶Ç´Â ½º·ÎƲ¸µ ¾ø´Â ¸®¼Ò½º ÇÒ´ç Ãë¾àÁ¡. ÀÌ ¹®Á¦´Â 2.4.30ºÎÅÍ 2.4.66±îÁöÀÇ Apache HTTP Server ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-29168) - Apache HTTP Server 2.4.66 ¹× ÀÌÀü ¹öÀüÀÇ mod_dav_lock¿¡ Á¸ÀçÇÏ´Â NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶ Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ ¿äûÀ» º¸³» ¼¹öÀÇ ÀÛµ¿À» Áß´Ü(crash)½Ãų ¼ö ÀÖ½À´Ï´Ù. mod_dav_lockÀº mod_dav ¶Ç´Â mod_dav_fs¿¡¼ ³»ºÎÀûÀ¸·Î »ç¿ëµÇÁö ¾Ê½À´Ï´Ù. mod_dav_lockÀÇ À¯ÀÏÇÏ°Ô ¾Ë·ÁÁø »ç¿ë »ç·Ê´Â 1.2.0 ÀÌÀü ¹öÀüÀÇ Apache Subversion¿¡ Æ÷ÇÔµÈ mod_dav_svn»ÓÀ̾ú½À´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.66 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇϰųª mod_dav_lockÀ» Á¦°ÅÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-29169)
* Âü°í »çÀÌÆ®: https://httpd.apache.org/security/vulnerabilities_24.html https://nvd.nist.gov/vuln/detail/CVE-2026-28780 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28780 https://nvd.nist.gov/vuln/detail/CVE-2026-23918 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23918 https://nvd.nist.gov/vuln/detail/CVE-2026-24072 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24072 https://nvd.nist.gov/vuln/detail/CVE-2026-29168 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29168 https://nvd.nist.gov/vuln/detail/CVE-2026-29169 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29169
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 2.4.67 ÀÌÀü 2.4.x ¹öÀü Any operating system Any version |
| ÇØ°áÃ¥ |
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(2.4.67 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2026-23918,CVE-2026-24072,CVE-2026-28780,CVE-2026-29168,CVE-2026-29169,CVE-2026-33006,CVE-2026-33007,CVE-2026-33523,CVE-2026-33857 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|