Ãë¾àÁ¡ID |
22671 |
À§Çèµµ |
30 |
Æ÷Æ® |
8080,3128 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Webproxy |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®´Â 3.4.8 ÀÌÀüÀÇ Squid Web Proxy CacheÀÇ ¹öÀüÀ» °¡µ¿ ÁßÀÌ´Ù. Squid´Â Linux¿Í Unix ¹èÆ÷ÆǵéÀ» À§ÇÑ ¹«·á À¥ ÇÁ·Ï½Ã ¼¹öÀÌ´Ù. Squid Web Proxy Cache 3.4.8 ÀÌÀü ¹öÀüµéÀº ´ÙÀ½°ú °°ÀÌ ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù.
- SNMP ó¸® ÄÄÆ÷³ÍÆ®¿¡ off-by-one ¿À¹öÇÃ·Î¿ì ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ °ø°ÝÀڴ Ưº°È÷ Á¶ÀÛµÈ UDP SNMP ¿äûÀ¸·Î ¼ºñ½º °ÅºÎ¸¦ ¹ß»ý½ÃÅ°°Å³ª, ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. (CVE-2014-6270)
- ICMP¿Í ICMPv6ÀÇ ÀÀ´äÀ» ó¸®ÇÒ ¶§ pinger¿¡¼ ¹è¿ Àε¦½Ì ¿À·ù°¡ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇØ °ø°ÝÀÚ´Â ¹Î°¨ÇÑ Á¤º¸¸¦ ȹµæÇϰųª ¼ºñ½º °ÅºÎ¸¦ ¹ß»ý½Ãų ¼ö ÀÖ´Ù. (CVE-2014-7141)
- ICMP¿Í ICMPv6ÀÇ ÀÀ´äÀ» ó¸®ÇÒ ¶§ icmp/Icmp4.cc ÆÄÀÏÀÇ 'Icmp4::Recv' ÇÔ¼ö¿¡¼ ¿À·ù°¡ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇØ °ø°ÝÀÚ´Â ¹Î°¨ÇÑ Á¤º¸¸¦ ȹµæÇϰųª ¼ºñ½º °ÅºÎ¸¦ ¹ß»ý½Ãų ¼ö ÀÖ´Ù. (CVE-2014-7142)
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Squid Web Proxy Cache ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.squid-cache.org/Advisories/ http://www.squid-cache.org/Advisories/SQUID-2014_3.txt http://www.squid-cache.org/Advisories/SQUID-2014_4.txt
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: National Science Foundation, Squid Web Proxy Cache 3.4.8 ÀÌÀü ¹öÀüµé Linux Any version Unix Any version |
ÇØ°áÃ¥ |
Squid À¥ »çÀÌÆ®ÀÎhttp://www.squid-cache.org/Versions/v3/3.4/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â SquidÀÇ °¡Àå ÃֽŠ¹öÀü(3.4.8 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2014-6270,CVE-2014-7141,CVE-2014-7142 (CVE) |
°ü·Ã URL |
69686,69688,70022 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|