English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210293
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀÌ 2.4.67 ÀÌÀü ¹öÀüÀÔ´Ï´Ù. µû¶ó¼­ 2.4.67 ±Ç°í¹®¿¡¼­ ¾ð±ÞµÈ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- Apache HTTP ServerÀÇ mod_proxy_ajp¿¡ Á¸ÀçÇÏ´Â Èü ±â¹Ý ¹öÆÛ ¿À¹öÇ÷Î(Heap-based Buffer Overflow) Ãë¾àÁ¡. mod_proxy_ajp°¡ ¾Ç¼º AJP ¼­¹ö¿¡ ¿¬°áµÇ´Â °æ¿ì, ÇØ´ç AJP ¼­¹ö´Â ¾ÇÀÇÀûÀÎ AJP ¸Þ½ÃÁö¸¦ mod_proxy_ajp·Î ´Ù½Ã Àü¼ÛÇÏ¿© Èü ±â¹Ý ¹öÆÛÀÇ ³¡À» ³Ñ¾î °ø°ÝÀÚ°¡ Á¦¾îÇÏ´Â 4¹ÙÀÌÆ®¸¦ ¾²µµ·Ï À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦´Â 2.4.66 ÀÌÇÏÀÇ Apache HTTP Server ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-28780)
- HTTP/2 ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â Apache HTTP Server¿¡ Á¸ÀçÇÏ´Â ÀÌÁß ÇØÁ¦(Double Free) ¹× ¿ø°Ý ÄÚµå ½ÇÇà(RCE) °¡´É¼º Ãë¾àÁ¡. ÀÌ ¹®Á¦´Â Apache HTTP Server 2.4.66 ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-23918)
- Apache HTTP 2.4.66 ¹× ÀÌÀü ¹öÀüÀÇ ´Ù¾çÇÑ ¸ðµâ¿¡ Á¸ÀçÇÏ´Â ±ÇÇÑ »ó½Â ¹ö±×·Î ÀÎÇØ ·ÎÄà .htaccess ÀÛ¼ºÀÚ°¡ httpd »ç¿ëÀÚÀÇ ±ÇÇÑÀ¸·Î ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ½À´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-24072)
- OCSP ÀÀ´ä µ¥ÀÌÅ͸¦ ÅëÇÑ Apache HTTP Server mod_mdÀÇ Á¦ÇÑ ¶Ç´Â ½º·ÎƲ¸µ ¾ø´Â ¸®¼Ò½º ÇÒ´ç Ãë¾àÁ¡. ÀÌ ¹®Á¦´Â 2.4.30ºÎÅÍ 2.4.66±îÁöÀÇ Apache HTTP Server ¹öÀü¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.67 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-29168)
- Apache HTTP Server 2.4.66 ¹× ÀÌÀü ¹öÀüÀÇ mod_dav_lock¿¡ Á¸ÀçÇÏ´Â NULL Æ÷ÀÎÅÍ ¿ªÂüÁ¶ Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ ¿äûÀ» º¸³» ¼­¹öÀÇ ÀÛµ¿À» Áß´Ü(crash)½Ãų ¼ö ÀÖ½À´Ï´Ù. mod_dav_lockÀº mod_dav ¶Ç´Â mod_dav_fs¿¡¼­ ³»ºÎÀûÀ¸·Î »ç¿ëµÇÁö ¾Ê½À´Ï´Ù. mod_dav_lockÀÇ À¯ÀÏÇÏ°Ô ¾Ë·ÁÁø »ç¿ë »ç·Ê´Â 1.2.0 ÀÌÀü ¹öÀüÀÇ Apache Subversion¿¡ Æ÷ÇÔµÈ mod_dav_svn»ÓÀ̾ú½À´Ï´Ù. »ç¿ëÀÚ´Â ÀÌ ¹®Á¦¸¦ ÇØ°áÇÑ 2.4.66 ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇϰųª mod_dav_lockÀ» Á¦°ÅÇÏ´Â °ÍÀÌ ±ÇÀåµË´Ï´Ù. (CVE-2026-29169)

* Âü°í »çÀÌÆ®:
https://httpd.apache.org/security/vulnerabilities_24.html
https://nvd.nist.gov/vuln/detail/CVE-2026-28780
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28780
https://nvd.nist.gov/vuln/detail/CVE-2026-23918
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23918
https://nvd.nist.gov/vuln/detail/CVE-2026-24072
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24072
https://nvd.nist.gov/vuln/detail/CVE-2026-29168
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29168
https://nvd.nist.gov/vuln/detail/CVE-2026-29169
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29169

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 2.4.67 ÀÌÀü 2.4.x ¹öÀü
Any operating system Any version
ÇØ°áÃ¥ Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(2.4.67 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2026-23918,CVE-2026-24072,CVE-2026-28780,CVE-2026-29168,CVE-2026-29169,CVE-2026-33006,CVE-2026-33007,CVE-2026-33523,CVE-2026-33857 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)