English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22929
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ Apache httpd ¹öÀüÀº 2.4.41 ÀÌÀüÀÔ´Ï´Ù. ÇØ´ç ¹öÀüÀº ´ÙÁß Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.

-HTTP/2 (2.4.20-2.4.39) ¸Å¿ì Ãʱâ Ǫ½Ã (¿¹ : H2PushResource·Î ±¸¼º)´Â Ǫ½Ã ¿äû Ç®ÀÇ ¸Þ¸ð¸®¸¦ µ¤¾î ½á¼­ Ãæµ¹À» ÀÏÀ¸Å³ ¼ö ÀÖ½À´Ï´Ù. º¹»ç µÈ ¸Þ¸ð¸®´Â Ŭ¶óÀ̾ðÆ®°¡ Á¦°ø ÇÑ µ¥ÀÌÅÍ°¡ ¾Æ´Ï¶ó ±¸¼ºµÈ Ǫ½Ã ¸µÅ© Çì´õ °ªÀÇ ¸Þ¸ð¸®ÀÔ´Ï´Ù. (CVE-2019-10081)

-ÀϺΠHTTP/2 ±¸ÇöÀº Á¦ÇѵÇÁö ¾ÊÀº interal µ¥ÀÌÅÍ ¹öÆÛ¸µ¿¡ Ãë¾àÇÏ¿© ¼­ºñ½º °ÅºÎ·Î À̾îÁú ¼ö ÀÖ½À´Ï´Ù. °ø°ÝÀÚ´Â HTTP/2 âÀ» ¿­¾î¼­ ÇǾ Á¦¾à¾øÀÌ Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. TCP âÀ» ´ÝÀº »óÅ¿¡¼­ ÇǾ ½ÇÁ¦·Î ¹ÙÀÌÆ®¸¦ ¾µ ¼ö´Â ¾ø½À´Ï´Ù. ±×·± ´ÙÀ½ °ø°ÝÀÚ´Â Å« ÀÀ´ä °³Ã¼¿¡ ´ëÇÑ ¿äû ½ºÆ®¸²À» º¸³À´Ï´Ù. ¼­¹ö°¡ ÀÀ´äÀ» ´ë±âÇÏ´Â ¹æ¹ý¿¡ µû¶ó °úµµÇÑ ¸Þ¸ð¸®, CPU ¶Ç´Â µÑ ´Ù¸¦ ¼Òºñ ÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2019-9517)

* Âü°í »çÀÌÆ®:
https://lists.apache.org/thread.html/ec97fdfc1a859266e56fef084353a34e0a0b08901b3c1aa317a43c8c@%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache HTTP Server 2.4.41 ÀÌÀü 2.4.x ¹öÀü
Any operating system Any version
ÇØ°áÃ¥ Apache Software Foundation À¥ »çÀÌÆ®ÀÎ http://httpd.apache.org/download.cgi ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Apache HTTP ServerÀÇ °¡Àå ÃֽŠ¹öÀü(2.4.41 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2019-9517,CVE-2019-10081,CVE-2019-10082,CVE-2019-10092,CVE-2019-10097,CVE-2019-10098 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)