|  Ãë¾àÁ¡ID  | 
	             22269  | 
             
             
 	            |  À§Çèµµ  | 
	             40  |  
             
            
 	            |  Æ÷Æ®  | 
	             3128,8080  | 
             		
            	
 	            |  ÇÁ·ÎÅäÄÝ  | 
	             TCP  | 
             	
            	
 	            |  ºÐ·ù  | 
	             Webproxy  | 
             			
            	
 	            |  »ó¼¼¼³¸í  | 
	             ÇØ´ç Squid caching proxyÀÇ ¹öÀü¿¡ µû¸£¸é ¼¹ö´Â NTLM ÀÎÁõ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Squid´Â Linux ¹èÆ÷ÆÇµéÀ» À§ÇÑ ¹«·á À¥ ÇÁ·Ï½Ã ¼¹öÀÌ´Ù. Squid Web Proxy Cache 2.5-STABLE ±×¸®°í 3-PRE ¹öÀüµéÀº NTLM ÀÎÁõ Á¤º¸µéÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ °áÇÔÀº »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» º¹»çÇÒ ¶§ ÀûÀýÇÏ°Ô ¹öÆÛ °æ°èÄ¡¸¦ °Ë»çÇÏÁö ¸øÇÏ´Â ¾îÇø®ÄÉÀÌ¼Ç »óÀÇ ¿À·ù°¡ ¿øÀÎÀÌ µÈ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Squid Proxy°¡ NTLM ÀÎÁõ µµ¿ì¹Ì(helper)¸¦ »ç¿ëÇÏ´Â °ÍÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ» °æ¿ì, ´ë»ó ½Ã½ºÅÛÀ» ÇØÅ·ÇÒ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ¾ÆÁÖ ±ä ÆÐ½º¿öµå ("pass" º¯¼ö)¸¦ º¸³» ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
  * ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid proxy ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
  * Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0191.html
  * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: National Science Foundation, Squid Web Proxy Cache 2.5-STABLE  National Science Foundation, Squid Web Proxy Cache 3-PRE  Linux Any version Unix Any version  | 
             
            	
 	            |  ÇØ°áÃ¥  | 
	             Squid Web Proxy Cache 2.5-STABLEÀÇ °æ¿ì: ´ÙÀ½ °ø½Ä Squid-2.5 Patches »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE5-ntlm_auth_overflow.patch
  Red Hat LinuxÀÇ °æ¿ì: ´ÙÀ½ Red Hat Security Advisory RHSA-2004:242-06À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: https://rhn.redhat.com/errata/RHSA-2004-242.html
  SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE Security Announcement SuSE-SA:2004:016À» Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_16_squid.html
  Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft Security Advisory MDKSA-2004:059¸¦ Âü°íÇÏ¿© °¡Àå ÃÖ½ÅÀÇ Squid ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
 
  Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200406-13À» ÂüÁ¶ÇÏ¿© SquidÀÇ °¡Àå ÃֽйöÀü(2.5.5-r2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml
  ±âŸ: Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¸¦ ¾Ë¾Æº»´Ù.  |   
             		
            	
 	            |  °ü·Ã URL  | 
	             CVE-2004-0541 (CVE) | 
             		
            	
 	            |   °ü·Ã URL  | 
	            10500 (SecurityFocus) |  
             
            
 	            |   °ü·Ã URL  | 
	            16360 (ISS) | 
             
    	
         
         |