| 
   
            
 	            | Ãë¾àÁ¡ID | 22349 |   
 	            | À§Çèµµ | 40 |  
 	            | Æ÷Æ® | 7778, ... |  	
 	            | ÇÁ·ÎÅäÄÝ | TCP |  	
 	            | ºÐ·ù | WWW |  	
 	            | »ó¼¼¼³¸í | ÇØ´ç Oracle9iAS Application ¼¹ö´Â Á¢±Ù Á¦ÇÑ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Oracle9iAS Application ¼¹ö´Â Á¦ÇÑµÈ URIµéÀÇ ¸®½ºÆ®¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù. À̰ÍÀº 'mod_access' À» ÀÌ¿ëÇÏ¿© °¡´ÉÇÏ´Ù. Oracle9iAS Application ¼¹ö 1.0.2¿¡¼ 10.x±îÁöÀÇ ¹öÀüµéÀº UseWebcacheIPÀÌ »ç¿ëµÇ°í ÀÖÁö ¾ÊÀ» ¶§, Æ÷Æ® 7778¿¡ ÀÖ´Â Web Cache¸¦ ÀÌ¿ëÇÒ ¶§ Á¸ÀçÇÏ´Â Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ mod_access Á¦ÇѵéÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Á÷Á¢ÀûÀ¸·Î Æ÷Æ® 7779 »óÀÇ Oracle HTTP Server°¡ ¾Æ´Ñ Æ÷Æ® 7778 »óÀÇ Web Cache¸¦ ÀÌ¿ëÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼¹ö »óÀÇ Á¦ÇÑµÈ URLµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. 
 * Âü°í »çÀÌÆ®:
 http://www.red-database-security.com/advisory/oracle_webcache_bypass.html
 http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=263943.1
 http://secunia.com/advisories/15143/
 
 * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
 Oracle, Oracle9iAS Application Server 1.0.2¿¡¼ 10.x±îÁöÀÇ ¹öÀüµé
 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
 |  	
 	            | ÇØ°áÃ¥ | Oracle Support À¥ ÆäÀÌÁöÀÎ http://www.oracle.com/support/index.html ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. 
 Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, Oracle HTTP Server(OHS)ÀÇ httpd.conf¿¡ "UseWebCacheIP ON"À» Ãß°¡ÇÑ´Ù.
 |  	
 	            | °ü·Ã URL | CVE-2005-1383 (CVE) |  	
 	            | °ü·Ã URL | 13418 (SecurityFocus) |  
 	            | °ü·Ã URL | 20311 (ISS) |  |