|  Ãë¾àÁ¡ID  | 
	             22267  | 
             
             
 	            |  À§Çèµµ  | 
	             40  |  
             
            
 	            |  Æ÷Æ®  | 
	             80, ...  | 
             		
            	
 	            |  ÇÁ·ÎÅäÄÝ  | 
	             TCP  | 
             	
            	
 	            |  ºÐ·ù  | 
	             WWW  | 
             			
            	
 	            |  »ó¼¼¼³¸í  | 
	             ÇØ´ç Apache HTTP À¥ ¼¹ö´Â mode_proxy ¸ðµâ »óÀÇ Èü(Heap) ±â¹Ý ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache ¹öÀü 1.3.26°ú 1.3.31 »çÀÌÀÇ À¥ ¼¹öµé¿¡´Â ¿ø°ÝÁö °ø°ÝÀڵ鿡 ÀÇÇØ ¼ºñ½º °ÅºÎ °ø°Ý ¶Ç´Â ÀÓÀÇÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡Àº À¥ ¼¹ö°¡ ¿Ã¹Ù¸£°Ô Content-Length Çʵ带 °Ë»çÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº mod_proxy¸¦ ÅëÇØ À߸øµÈ Content-Length °ªÀ» ¹ÝȯÇÏ´Â ¾ÇÀÇÀûÀÎ ¼¹ö¿¡ ¿¬°áÇÏ¿© ÇØ´ç ¿ø°ÝÁö Apache À¥ ¼¹ö°¡ Àß Á¶ÀÛµÈ À½¼öÀÇ Content-Length °ªÀ» Àü´Þ¹Þµµ·Ï ÇÔÀ¸·Î½á, ¼ºñ½º °ÅºÎ ¹× ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ ÄÚµå ½ÇÇ൵ °¡´ÉÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.  
  * ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ¸¸¾à Apache ¼¹ö°¡ mod_proxy ¸ðµâÀ» ·ÎµåÇÏÁö ¾Ê¾Ò´Ù¸é ÀÌ Ãë¾àÁ¡Àº ¹«½ÃÇÑ´Ù.
  * Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=apache-httpd-dev&m=108687304202140 http://www.guninski.com/modproxy1.html
  * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 1.3.26 ~ 1.3.31  Debian Linux 3.0  Gentoo Linux Any version  OpenPKG 1.3, 2.0, CURRENT Red Hat Advanced Workstation 2.1AS, Enterprise Linux 2.1AS, 2.1ES, 2.1WS  ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü  | 
             
            	
 	            |  ÇØ°áÃ¥  | 
	             Red Hat Linux ÀÇ °æ¿ì: ´ÙÀ½ÀÇ Red Hat º¸¾È ±Ç°í¹® RHSA-2004:245-14 ¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2004-245.html
  Debian GNU/Linux 3.0 (woody) ÀÇ °æ¿ì: ´ÙÀ½ÀÇ Debian º¸¾È ±Ç°í¹® DSA-525-1¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.26-0woody5 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù: http://www.debian.org/security/2004/dsa-525
  Gentoo Linux Security ÀÇ °æ¿ì: ´ÙÀ½ÀÇ Gentoo Linux º¸¾È ±Ç°í¹® GLSA 200406-16¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Apache ÆÐŰÁö(1.3.31-r2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200406-16.xml
  ±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵å Á¤º¸¸¦ ±¸ÇÏ¿©¾ß ÇÑ´Ù.  |   
             		
            	
 	            |  °ü·Ã URL  | 
	             CVE-2004-0492 (CVE) | 
             		
            	
 	            |   °ü·Ã URL  | 
	            10508 (SecurityFocus) |  
             
            
 	            |   °ü·Ã URL  | 
	            16387 (ISS) | 
             
    	
         
         |