English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22253
À§Çèµµ 30
Æ÷Æ® 8080,3128
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Webproxy
»ó¼¼¼³¸í ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼­¹ö´Â NULL ¹®ÀÚ¸¦ ÅëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼­¹öÀÌ´Ù. Squid Web Proxy Cache 2.5STABLE4 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾×¼¼½º Á¦¾î ¸®½ºÆ® (ACL)µéÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. %00 (null) ¹®ÀÚ¸¦ Æ÷ÇÔÇÑ ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ¸íÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â url_regex ACLµéÀ» ¿ìȸÇÒ ¼ö ÀÖÀ¸¸ç ´Ù¸¥ Á¦¾îµÈ ÀÚ¿øµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=bugtraq&m=108075225114097&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=108084935904110&w=2
http://www.securitytracker.com/alerts/2004/Mar/1009267.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
National Science Foundation Squid Web Proxy Cache 2.5.STABLE4 ÀÌÇÏÀÇ 2.x ¹öÀüµé
Debian Linux 3.0
Red Hat Linux 9
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Squid Proxy Cache Security Update Advisory SQUID-2004:1À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.stable5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.squid-cache.org/Advisories/SQUID-2004_1.txt

Red Hat Linux 9ÀÇ °æ¿ì:
´ÙÀ½ Red Hat Security Advisory RHSA-2004:134-01À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.STABLE1-3.9 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/105869/170/

Debian/GNU Linux 3.0 (woody)ÀÇ °æ¿ì:
´ÙÀ½ Debian Security Advisory DSA-474-1À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.4.6-2woody2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.debian.org/security/2004/dsa-474


±âŸ:
Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.
°ü·Ã URL CVE-2004-0189 (CVE)
°ü·Ã URL 9778 (SecurityFocus)
°ü·Ã URL 15366 (ISS)