English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22018
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache À¥¼­¹öÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â Chunked Encoding ¹öÆÛ ¿À¹öÇ÷ο쿡 Ãë¾àÇÏ´Ù. ¼º°øÀûÀÎ µµ¿ëÀº À¥¼­¹öÀÇ ³»¿ë º¯Á¶, ¼­ºñ½º °ÅºÎ, ³ª¾Æ°¡ ½Ã½ºÅÛ Àå¾Ç±îÁö °¡´ÉÇÏ´Ù.
Apache À¥¼­¹ö´Â Apache Software Foundation¿¡ ÀÇÇØ À¯Áöº¸¼ö µÈ´Ù. Apache´Â °ø°³ ¼Ò½º ±â¹ÝÀÇ ¸Å¿ì ÀαâÀÖ´Â À¥¼­¹öÀÌ´Ù.
¹®Á¦ÀÖ´Â Apache À¥¼­¹ö ¹öÀüµéÀº "chunked" encodingÀÇ Å©±â¸¦ °è»êÇÏ´Â ¸ÞÄ¿´ÏÁò¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Chunked encodingÀº Ŭ¶óÀÌ¾ðÆ®°¡ °¡º¯ÀûÀÎ Å©±âÀÇ µ¥ÀÌÅÍÀÇ µ¢¾î¸®("chunk")¸¦ ¸¸µé¾î À̸¦ Àü¼ÛÇϱâ Àü¿¡ µ¥ÀÌÅÍÀÇ Å©±â¸¦ À¥¼­¹ö¿¡ ¾Ë·ÁÁÖ°í, À¥¼­¹ö°¡ ¾Ë¸ÂÀº Å©±âÀÇ ¹öÆÛ¸¦ ÇÒ´çÇÏ°Ô Çϴµ¥ ÀÌ °úÁ¤À» ¸»ÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº ÀÎÀԵǴ µ¥ÀÌÅÍ µ¢¾î¸®ÀÇ Å©±â¸¦ À߸ø ÇØ¼®ÇÏ´Â ¼ÒÇÁÆ®¿þ¾îÀû °áÇÔÀ¸·Î °ø°ÝÀÚ°¡ ¿ø°ÝÀ¸·Î ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸ÄÑ Ãë¾àÇÑ À¥¼­¹ö»ó¿¡¼­ ÀÓÀÇÀÇ Äڵ尡 ¼öÇàµÇ°Ô Çϰųª ¼­ºñ½º °ÅºÎ¸¦ À¯¹ßÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2002-17.html
http://www.kb.cert.org/vuls/id/944335
http://httpd.apache.org/info/security_bulletin_20020617.txt


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache ÄÚµå ¹öÀü 1.3 ~ 1.3.24 ¿¡ ±â¹ÝÀ» µÐ À¥¼­¹öµé
Apache ÄÚµå ¹öÀü 2.0 ~ 2.0.36 ¿¡ ±â¹ÝÀ» µÐ À¥¼­¹öµé
IBM HTTP Server (IHS) v1.3.19 ÀÌÇÏÀÇ ¸ðµç ¹öÀüµé
Linux Any version
UNIX Any version
Windows Any version
ÇØ°áÃ¥ Apache HTTP Server 1.x ±×¸®°í 2.xÀÇ °æ¿ì:
´ÙÀ½ Apache Software FoundationÀÇ ´Ù¿î·Îµå »çÀÌÆ®, http://httpd.apache.org ¿¡¼­ Apache HTTP ServerÀÇ °¡Àå ÃֽйöÀü(1.3.26 ȤÀº ÀÌÈÄ, ȤÀº 2.0.39 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:

IBM HTTP ServerÀÇ °æ¿ì:
´ÙÀ½ IBM À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ IBM HTTP Server·Î ¾÷±×·¹À̵å ÇÑ´Ù.
http://www-01.ibm.com/software/webservers/httpservers/

±âŸ:
º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù. ȤÀº ´ÙÀ½ CERT Advisory CA-2002-17À» ÂüÁ¶ÇÑ´Ù:
http://www.cert.org/advisories/CA-2002-17.html
°ü·Ã URL CVE-2002-0392 (CVE)
°ü·Ã URL 5033 (SecurityFocus)
°ü·Ã URL 9249 (ISS)