| Ãë¾àÁ¡ID |
22253 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
8080,3128 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Webproxy |
| »ó¼¼¼³¸í |
ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â NULL ¹®ÀÚ¸¦ ÅëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ÇÁ·Ï½Ã ¼¹öÀÌ´Ù. Squid Web Proxy Cache 2.5STABLE4 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾×¼¼½º Á¦¾î ¸®½ºÆ® (ACL)µéÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. %00 (null) ¹®ÀÚ¸¦ Æ÷ÇÔÇÑ ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ¸íÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â url_regex ACLµéÀ» ¿ìȸÇÒ ¼ö ÀÖÀ¸¸ç ´Ù¸¥ Á¦¾îµÈ ÀÚ¿øµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=108075225114097&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=108084935904110&w=2 http://www.securitytracker.com/alerts/2004/Mar/1009267.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: National Science Foundation Squid Web Proxy Cache 2.5.STABLE4 ÀÌÇÏÀÇ 2.x ¹öÀüµé Debian Linux 3.0 Red Hat Linux 9 Unix Any version Linux Any version |
| ÇØ°áÃ¥ |
´ÙÀ½ Squid Proxy Cache Security Update Advisory SQUID-2004:1À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.stable5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.squid-cache.org/Advisories/SQUID-2004_1.txt
Red Hat Linux 9ÀÇ °æ¿ì: ´ÙÀ½ Red Hat Security Advisory RHSA-2004:134-01À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.STABLE1-3.9 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.linuxsecurity.com/content/view/105869/170/
Debian/GNU Linux 3.0 (woody)ÀÇ °æ¿ì: ´ÙÀ½ Debian Security Advisory DSA-474-1À» Âü°íÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.4.6-2woody2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-474
±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù. |
| °ü·Ã URL |
CVE-2004-0189 (CVE) |
| °ü·Ã URL |
9778 (SecurityFocus) |
| °ü·Ã URL |
15366 (ISS) |
|