Ãë¾àÁ¡ID |
22813 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â Apache Tomcat (6.0.x)ÀÇ 6.0.24. ÀÌÀü ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç, ´Ù¼öÀÇ Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â´Ù.
- 'Sendfile' ¸¦ »ç¿ëÇÒ ¶§, ÆÄÀÌÇÁ ¶óÀÎ ¿äûÀ» ´Ù·ç¸é¼ ƯÁ¤µÇÁö ¾ÊÀº °áÇÔÀÌ Á¸ÀçÇÑ´Ù. ¸¸¾à 'Sendfile" 󸮰¡ ºü¸£°Ô ¿Ï·áµÇ¸é, ÇÁ·Î¼¼¼°¡ ÇÁ·Î¼¼¼ ij½¬¿¡ Áߺ¹µÇ¾î Ãß°¡ µÉ °¡´É¼ºÀÌ Á¸ÀçÇÑ´Ù. ÀÌ°ÍÀº À¯È¿ÇÏÁö ¾ÊÀº ÀÀ´äÀ̳ª, Á¤º¸ ³ëÃâÀ» ¾ß±âÇÒ ¼ö ÀÖ´Ù. (CVE-2017-5647)
- "DefaultServlet" ±¸ÇöÀÇ ¿¡·¯ ÆäÀÌÁö ¸ÞÄ¿´ÏÁò¿¡ ƯÁ¤µÇÁö ¾ÊÀº °áÇÔÀÌ Ä¿½ºÅÒ ¿¡·¯ ÆäÀÌÁöÀÇ »èÁ¦³ª ±³Ã¼¸¦ Æ÷ÇÔÇÑ ¿øÄ¡ ¾Ê´Â ºÎÀÛ¿ëÀ» ¾ß±âÇϴ Ư¼ö Á¦ÀÛµÈ HTTP ¿äûÀ» Çã¿ëÇÑ´Ù. (CVE-2017-5664)
- ƯÁ¤µÇÁö ¾ÊÀº °áÇÔÀÌ "readonly=false"¿Í HTTP PUT ¿äû Çã¿ëÀ¸·Î ¼³Á¤µÈ ¼ºí¸´ ÄÁÅؽºÆ®¿¡ ¿µÇâÀ» ³¢Ä£´Ù. °ø°ÝÀÚ´Â ÇØ´ç ÄÁÅؽºÆ®·Î JSP ÆÄÀÏ ¾÷·Îµå ÇÏ°í, ºÎÁ¤Äڵ带 ½ÇÇà ÇÒ ¼ö ÀÖ´Ù. (CVE-2017-12615, CVE-2017-12617)
* Âü°í »çÀÌÆ®: https://lists.apache.org/thread.html/5796678c5a773c6f3ff57c178ac247d85ceca0dee9190ba48171451a@%3Cusers.tomcat.apache.org%3E
* ¿µÇâ¹Þ´Â Ç÷§Æû: Apache Tomcat Server versions 6.0.x prior to 6.0.24 Any operating system Any version |
ÇØ°áÃ¥ |
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://tomcat.apache.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache Tomcat ServerÀÇ °¡Àå ÃֽŠ¹öÀü(6.0.24 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2017-5647,CVE-2017-5664,CVE-2017-12615,CVE-2017-12617 (CVE) |
°ü·Ã URL |
98888,100901,100954 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|