English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22349
À§Çèµµ 40
Æ÷Æ® 7778, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle9iAS Application ¼­¹ö´Â Á¢±Ù Á¦ÇÑ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Oracle9iAS Application ¼­¹ö´Â Á¦ÇÑµÈ URIµéÀÇ ¸®½ºÆ®¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù. ÀÌ°ÍÀº 'mod_access' À» ÀÌ¿ëÇÏ¿© °¡´ÉÇÏ´Ù. Oracle9iAS Application ¼­¹ö 1.0.2¿¡¼­ 10.x±îÁöÀÇ ¹öÀüµéÀº UseWebcacheIPÀÌ »ç¿ëµÇ°í ÀÖÁö ¾ÊÀ» ¶§, Æ÷Æ® 7778¿¡ ÀÖ´Â Web Cache¸¦ ÀÌ¿ëÇÒ ¶§ Á¸ÀçÇÏ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ mod_access Á¦ÇѵéÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Á÷Á¢ÀûÀ¸·Î Æ÷Æ® 7779 »óÀÇ Oracle HTTP Server°¡ ¾Æ´Ñ Æ÷Æ® 7778 »óÀÇ Web Cache¸¦ ÀÌ¿ëÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­¹ö »óÀÇ Á¦ÇÑµÈ URLµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.red-database-security.com/advisory/oracle_webcache_bypass.html
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=263943.1
http://secunia.com/advisories/15143/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle, Oracle9iAS Application Server 1.0.2¿¡¼­ 10.x±îÁöÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Oracle Support À¥ ÆäÀÌÁöÀÎ http://www.oracle.com/support/index.html ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, Oracle HTTP Server(OHS)ÀÇ httpd.conf¿¡ "UseWebCacheIP ON"À» Ãß°¡ÇÑ´Ù.
°ü·Ã URL CVE-2005-1383 (CVE)
°ü·Ã URL 13418 (SecurityFocus)
°ü·Ã URL 20311 (ISS)