English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22946
À§Çèµµ 30
Æ÷Æ® 8080,3128
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Webproxy
»ó¼¼¼³¸í ¹è³Ê¿¡ µû¸£¸é ¿ø°Ý È£½ºÆ®¿¡¼­ ½ÇÇàµÇ´Â Squid ¹öÀüÀº 4.13 ÀÌÀü 2.x ¶Ç´Â 5.0.4 ÀÌÀü 5.xÀÔ´Ï´Ù. µû¶ó¼­ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ»¹Þ½À´Ï´Ù.

-HTTP ¹× HTTPS Æ®·¡ÇÈ Ã³¸®¿Í °ü·ÃµÈ ÀÔ·Â À¯È¿¼º °Ë»ç °áÇÔÀÌ ÀÖ¾î HTTP ¿äû ºÐÇÒÀ» Çã¿ëÇÏ¿© ij½Ã Æ÷ÀÌÁî ´×À» À¯¹ßÇÕ´Ï´Ù. (CVE-2020-15810)

-ij½Ã Æ÷ÀÌÁî ´×À¸·Î À̾îÁö´Â HTTP ¿äû ¹Ð¼ö¸¦ Çã¿ëÇÏ´Â HTTP ¹× HTTPS Æ®·¡ÇÈ Ã³¸®¿Í °ü·ÃµÈ ÀÔ·Â À¯È¿¼º °Ë»ç °áÇÔÀÌ Á¸ÀçÇÕ´Ï´Ù. (CVE-2020-15811)

* Âü°í »çÀÌÆ®:
https://github.com/squid-cache/squid/security/advisories/GHSA-c7p8-xqhm-49wv
https://github.com/squid-cache/squid/security/advisories/GHSA-3365-q9qx-f98m

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
National Science Foundation, Squid Web Proxy Cache 4.13 ÀÌÀü ¹öÀüµé
Linux Any version
Unix Any version
ÇØ°áÃ¥ Squid À¥ »çÀÌÆ®ÀÎ http://www.squid-cache.org/Versions/v3/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â SquidÀÇ °¡Àå ÃֽŠ¹öÀü(4.13 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2020-15810,CVE-2020-15811 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)