|
 |
[ °ø Áö ] RedHat °è¿ Apache Tomcat ½Å±Ô Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2016-10-18 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
RedHat °è¿ Apache Tomcat ½Å±Ô Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ
ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
¡à °³¿ä
o RedHatÞä´Â RedHat ±â¹Ý ½Ã½ºÅÛÀÇ Apache Tomcat¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥[1]
- RedHat Enterprise Linux 7 ±â¹Ý ½Ã½ºÅÛÀÌ ÇØ´çµÇ¸ç °ø°ÝÀÚ°¡ ÇØ´ç Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¿© ·ÎÄñÇÇÑ»ó½ÂÀ» ÅëÇØ ½Ã½ºÅÛ
Á¦¾î±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ½
¡à ¼³¸í
o tomcat.confÀÇ Ãë¾àÇÑ ÆÄÀÏ ±ÇÇÑÀ¸·Î ÀÎÇØ ¹ß»ýÇÒ ¼ö ÀÖ´Â ·ÎÄñÇÇÑ»ó½Â Ãë¾àÁ¡(CVE-2016-5425)
¡à ÇØ´ç ½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â Á¦Ç° ¹× ¹öÀü
- RedHat Enterprise Linux 7 ±â¹Ý ½Ã½ºÅÛÀÇ ±âº» ÀúÀå¼Ò Apache Tomcat 6/7/8 ¹öÀü
¡Ø ÇØ´ç OS : RedHat, CentOS, Fedora, Oracle Linux, openSUSE
¡à ÇØ°á ¹æ¾È
o ÇØ´ç º¥´õ»çÀÇ ÃֽŠApache Tomcat ÆÐŰÁö ¾÷µ¥ÀÌÆ®
o ÆÐŰÁö ¾÷µ¥ÀÌÆ®°¡ ºÒ°¡´ÉÇÑ »ç¿ëÀÚ´Â /usr/lib/tmpfiles.d/tomcat.conf ÆÄÀÏÀÇ ¾²±â±ÇÇÑÀ» Á¦°Å
- chmod 644 /usr/lib/tmpfiles.d/tomcat.conf ¸í·É¾î¸¦ ÅëÇØ ±ÇÇÑÀ» º¯°æ
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://access.redhat.com/security/cve/CVE-2016-5425
°¨»çÇÕ´Ï´Ù.
---------------------------------------------------------------------------
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|