Ãë¾àÁ¡ID |
22929 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀº 2.4.41 ÀÌÀüÀÔ´Ï´Ù. ÇØ´ç ¹öÀüÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
-HTTP/2 (2.4.20-2.4.39) ¸Å¿ì Ãʱâ Ǫ½Ã (¿¹ : H2PushResource·Î ±¸¼º)´Â Ǫ½Ã ¿äû Ç®ÀÇ ¸Þ¸ð¸®¸¦ µ¤¾î ½á¼ Ãæµ¹À» ÀÏÀ¸Å³ ¼ö ÀÖ½À´Ï´Ù. º¹»ç µÈ ¸Þ¸ð¸®´Â Ŭ¶óÀ̾ðÆ®°¡ Á¦°ø ÇÑ µ¥ÀÌÅÍ°¡ ¾Æ´Ï¶ó ±¸¼ºµÈ Ǫ½Ã ¸µÅ© Çì´õ °ªÀÇ ¸Þ¸ð¸®ÀÔ´Ï´Ù. (CVE-2019-10081)
-ÀϺΠHTTP/2 ±¸ÇöÀº Á¦ÇѵÇÁö ¾ÊÀº interal µ¥ÀÌÅÍ ¹öÆÛ¸µ¿¡ Ãë¾àÇÏ¿© ¼ºñ½º °ÅºÎ·Î À̾îÁú ¼ö ÀÖ½À´Ï´Ù. °ø°ÝÀÚ´Â HTTP/2 âÀ» ¿¾î¼ ÇǾ Á¦¾à¾øÀÌ Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. TCP âÀ» ´ÝÀº »óÅ¿¡¼ ÇǾ ½ÇÁ¦·Î ¹ÙÀÌÆ®¸¦ ¾µ ¼ö´Â ¾ø½À´Ï´Ù. ±×·± ´ÙÀ½ °ø°ÝÀÚ´Â Å« ÀÀ´ä °³Ã¼¿¡ ´ëÇÑ ¿äû ½ºÆ®¸²À» º¸³À´Ï´Ù. ¼¹ö°¡ ÀÀ´äÀ» ´ë±âÇÏ´Â ¹æ¹ý¿¡ µû¶ó °úµµÇÑ ¸Þ¸ð¸®, CPU ¶Ç´Â µÑ ´Ù¸¦ ¼Òºñ ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-9517)
* Âü°í »çÀÌÆ®: https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c@%3Cdev.httpd.apache.org%3E https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache HTTP Server 2.4.41 ÀÌÀü 2.4.x ¹öÀü Any operating system Any version |
ÇØ°áÃ¥ |
Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.41 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2019-9517,CVE-2019-10081,CVE-2019-10082,CVE-2019-10092,CVE-2019-10097,CVE-2019-10098 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|