Ãë¾àÁ¡ID |
22349 |
À§Çèµµ |
40 |
Æ÷Æ® |
7778, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Oracle9iAS Application ¼¹ö´Â Á¢±Ù Á¦ÇÑ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Oracle9iAS Application ¼¹ö´Â Á¦ÇÑµÈ URIµéÀÇ ¸®½ºÆ®¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù. ÀÌ°ÍÀº 'mod_access' À» ÀÌ¿ëÇÏ¿© °¡´ÉÇÏ´Ù. Oracle9iAS Application ¼¹ö 1.0.2¿¡¼ 10.x±îÁöÀÇ ¹öÀüµéÀº UseWebcacheIPÀÌ »ç¿ëµÇ°í ÀÖÁö ¾ÊÀ» ¶§, Æ÷Æ® 7778¿¡ ÀÖ´Â Web Cache¸¦ ÀÌ¿ëÇÒ ¶§ Á¸ÀçÇÏ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ mod_access Á¦ÇѵéÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Á÷Á¢ÀûÀ¸·Î Æ÷Æ® 7779 »óÀÇ Oracle HTTP Server°¡ ¾Æ´Ñ Æ÷Æ® 7778 »óÀÇ Web Cache¸¦ ÀÌ¿ëÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼¹ö »óÀÇ Á¦ÇÑµÈ URLµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.red-database-security.com/advisory/oracle_webcache_bypass.html http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=263943.1 http://secunia.com/advisories/15143/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle, Oracle9iAS Application Server 1.0.2¿¡¼ 10.x±îÁöÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Oracle Support À¥ ÆäÀÌÁöÀÎ http://www.oracle.com/support/index.html ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, Oracle HTTP Server(OHS)ÀÇ httpd.conf¿¡ "UseWebCacheIP ON"À» Ãß°¡ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-1383 (CVE) |
°ü·Ã URL |
13418 (SecurityFocus) |
°ü·Ã URL |
20311 (ISS) |
|