(VMware Issues Fix) mod_ssl Format String Error in 'ssl_engine_ext' May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1012918
|
|
SecurityTracker URL: http://securitytracker.com/id?1012918
|
|
CVE Reference: CAN-2004-0700
(Links to External Site)
|
|
OSVDB Reference: 7929
(Links to External Site)
|
Date: Jan 18 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: A format string vulnerability was reported in mod_ssl. In certain cases where Apache mod_proxy is also used, a remote user may be able to cause arbitrary code to be executed on the target user's system. VMware is affected.
Ralf S. Engelschall reported that if Apache is used as a proxy and an HTTPS URL such as 'https://foo%s.example.com/' is supplied
and a hostname 'foo%s' exists in the 'example.com' zone, the flaw can reportedly be triggered.
The flaw reportedly resides in
an error message call in 'ssl_engine_ext.c'.
The report credits Virulent <virulent@siyahsapka.org> with reporting a similar bug
(that was reportedly not exploitable) and triggering a review of the code.
|
Impact: A remote user may be able to cause arbitrary code to be executed on the target system in certain cases.
|
Solution: VMware has issued a fix for the VMware ESX Server.
VMware ESX Server 2.1.2 Security Update:
http://www.vmware.com/download/esx/esx212-10921update.html
VMware
ESX Server 2.0.1 Patch 1 Security Update:
http://www.vmware.com/download/esx/esx201-11429update.html
VMware ESX Server 1.5.2
Patch 6 Security Update:
http://www.vmware.com/download/esx/esx152-10816update.html
|
Cause: Input validation error, State error
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Tue, 18 Jan 2005 02:02:44 -0500
Subject: http://www.vmware.com/download/esx/esx212-10921update.html
|
http://www.vmware.com/download/esx/esx212-10921update.html
VMware ESX Server 2.1.2 Security Update
Last updated: 1/13/2005
This patch includes updates for ESX Server 2.1.2 that addresses the following security vulnerabilitie s:
* mod_ssl security exploit CAN-2004-0885 (See Knowledge Base Article 1555 for details.)
* mod_ssl security exploit CAN-2004-0700 (See Knowledge Base Article 1429 for details.)
* Linux security exploit CAN-2004-0415 (See Knowledge Base Article 1431 for details.)
In addition, this update removes a limitation on using more than 30 LUNs simultaneously.
There are a separate security updates for ESX Server 2.0.1 and 1.5.2 available as the VMware ESX Serv er 1.5.2 Patch 6 Security Update and VMware ESX Server 2.0.1 Security Update.
Linux Security Update for ESX Server 2.1.2, Build 9638
http://www.vmware.com/download/esx/esx201-11429update.html
VMware ESX Server 2.0.1 Patch 1 Security Update
Last updated: 1/13/2005
This patch includes updates for ESX Server 2.0.1 that addresses the following security vulnerabilitie s:
* mod_ssl security exploit CAN-2004-0885 (See Knowledge Base Article 1555 for details.)
* mod_ssl security exploit CAN-2004-0700 (See Knowledge Base Article 1429 for details.)
* Linux security exploit CAN-2004-0415 (See Knowledge Base Article 1431 for details.)
In addition, this update removes a limitation on using more than 30 LUNs simultaneously.
There are a separate security updates for ESX Server 2.1.2 and 1.5.2 available as the VMware ESX Serv er 1.5.2 Patch 6 Security Update and VMware ESX Server 2.1.2 Security Update.
Linux Security Update for ESX Server 2.0.1 Patch 1, Build 6403
http://www.vmware.com/download/esx/esx152-10816update.html
VMware ESX Server 1.5.2 Patch 6 Security Update
Last updated: 1/13/2005
This patch includes updates for ESX Server 1.5.2 that addresses the following security vulnerabilitie s:
* mod_ssl security exploit CAN-2004-0885 (See Knowledge Base Article 1555 for details.)
* mod_ssl security exploit CAN-2004-0700 (See Knowledge Base Article 1429 for details.)
* Linux security exploit CAN-2004-0415 (See Knowledge Base Article 1431 for details.)
In addition, this update removes a limitation on using more than 30 LUNs simultaneously.
There are separate security updates for ESX Server 2.1.2 and 2.0.1 available as the VMware ESX Server 2.1.2 Security Update and VMware ESX Server 2.0.1 Patch 1 Security Update.
Linux Security Update for ESX Server 1.5.2 Patch 6, Build 5835
|
|