Apache HTTP Server Privilege Escalation Vulnerability
Apache HTTP Server 2.4 릴리스 중 2.4.17부터 2.4.38까지의 버전에서 MPM event, worker 또는 prefork를 사용하는 경우, 낮은 권한의 자식 프로세스나 스레드에서 실행되는 코드(프로세스 내 스크립팅 인터프리터가 실행하는 스크립트 포함)가 scoreboard를 조작하여 부모 프로세스의 권한(일반적으로 root)으로 임의 코드를 실행할 수 있습니다. 비 Unix 시스템은 영향을 받지 않습니다.
Apache HTTP Server 2.4 릴리스 중 2.4.17부터 2.4.38까지의 버전에서 MPM event, worker 또는 prefork를 사용하는 경우, 낮은 권한의 자식 프로세스나 스레드에서 실행되는 코드(프로세스 내 스크립팅 인터프리터가 실행하는 스크립트 포함)가 scoreboard를 조작하여 부모 프로세스의 권한(일반적으로 root)으로 임의 코드를 실행할 수 있습니다. 비 Unix 시스템은 영향을 받지 않습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
영향 제품·버전
제품 Apache HTTP Server
영향 버전 Apache HTTP Server 2.4.17 to 2.4.38, >= 2.4.17 <= 2.4.38, 28, 29, 30, 14.04, 16.04, 18.04, 18.10, 9.0, 15.0, 42.3, 1.0, 3.11, 3.11 ppc64le, 8.0, 8.1, 8.2, 8.4, 8.6