SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Server/CGI)  >   Apache mod_digest Vendors:   Apache Software Foundation
(Slackware Issues Fix) Apache mod_digest May Validate Replayed Client Responses
SecurityTracker Alert ID:  1010147
SecurityTracker URL:  http://securitytracker.com/id/1010147
CVE Reference:   CAN-2003-0987   (Links to External Site)
Date:  May 13 2004
Impact:   User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 1.3.29 and prior versions
Description:   A vulnerability was reported in Apache mod_digest. The software may not correctly validate a client response, allowing a remote user to replay a response to gain access to an ostensibly protected system.

It is reported that mod_digest does not properly verify the nonce of a client response. A remote user may be able to replay a response to be authenticated in certain cases.

The report indicates that a remote user can capture the response from another section of the target web site (or another web site entirely). If the target user's username+password combination is the same and the realm is the same, the remote user can reportedly replay the digest response to be successfully authenticated.

Dirk-Willem van Gulik reported this flaw.

Impact:   A remote user may be able to be authenticated in certain cases.
Solution:   Slackware has released a fix.

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/apache-1.3.29-i386-2.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/apache-1.3.29-i386-2.tgz

Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/apache-1.3.29-i486-2.tgz

Updated packages for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/apache-1.3.31-i486-1.tgz
(these related packages are also available)
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/mod_ssl-2.8.17_1.3.31-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-4.3.6-i486-2.tgz

The MD5 signatures are:

Slackware 8.1 package:
53949a74ba3dd0a01271e3aa1178e082 apache-1.3.29-i386-2.tgz

Slackware 9.0 package:
64ede1f5637736842502301eb5bd727d apache-1.3.29-i386-2.tgz

Slackware 9.1 package:
ec5dad948d8b17b82b91d756a5c6b0f9 apache-1.3.29-i486-2.tgz

Slackware -current packages:
a925f8be7b8bbcb7e4a77e2ef755988a apache-1.3.31-i486-1.tgz
684626575e1c2a783b3d8d208876aab4 mod_ssl-2.8.17_1.3.31-i486-2.tgz
ad27d5f96281e11567184411b7c0720e php-4.3.6-i486-2.tgz

Vendor URL:  www.mail-archive.com/dev@httpd.apache.org/msg19007.html (Links to External Site)
Cause:   Authentication error
Underlying OS:   Linux (Slackware)

Message History:   This archive entry is a follow-up to the message listed below.
Feb 3 2004 Apache mod_digest May Validate Replayed Client Responses



 Source Message Contents

Date:  Wed, 12 May 2004 16:54:58 -0700 (PDT)
Subject:  [slackware-security] apache (SSA:2004-133-01)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security]  apache (SSA:2004-133-01)

New apache packages are available for Slackware 8.1, 9.0, 9.1, and -current to
fix security issues.  These include a possible denial-of-service attack as well
as the ability to possible pipe shell escapes through Apache's errorlog (which
could create an exploit if the error log is read in a terminal program that
does not filter such escapes).  We recommend that sites running Apache upgrade
to the new Apache package.

More details about these issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0987
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0174
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0993


Here are the details from the Slackware 9.1 ChangeLog:
+--------------------------+
Wed May 12 13:06:39 PDT 2004
patches/packages/apache-1.3.29-i486-2.tgz:  Patched four security issues
  in the Apache web server as noted on http://httpd.apache.org.
  These security fixes were backported from Apache 1.3.31:

    In mod_digest, verify whether the nonce returned in the client
    response is one we issued ourselves.  This problem does not affect
    mod_auth_digest. (CAN-2003-0987)

    Escape arbitrary data before writing into the errorlog.  (CAN-2003-0020)

    Fix starvation issue on listening sockets where a short-lived connection
    on a rarely-accessed listening socket will cause a child to hold the
    accept mutex and block out new connections until another connection
    arrives on that rarely-accessed listening socket.  (CAN-2004-0174)

    Fix parsing of Allow/Deny rules using IP addresses without a netmask;
    issue is only known to affect big-endian 64-bit platforms (CAN-2003-0993)

  For more details, see:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0987
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0020
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0174
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0993

  (* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/apache-1.3.29-i386-2.tgz

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/apache-1.3.29-i386-2.tgz

Updated package for Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/apache-1.3.29-i486-2.tgz

Updated packages for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/apache-1.3.31-i486-1.tgz
(these related packages are also available)
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/mod_ssl-2.8.17_1.3.31-i486-2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-4.3.6-i486-2.tgz


MD5 signatures:
+-------------+

Slackware 8.1 package:
53949a74ba3dd0a01271e3aa1178e082  apache-1.3.29-i386-2.tgz

Slackware 9.0 package:
64ede1f5637736842502301eb5bd727d  apache-1.3.29-i386-2.tgz

Slackware 9.1 package:
ec5dad948d8b17b82b91d756a5c6b0f9  apache-1.3.29-i486-2.tgz

Slackware -current packages:
a925f8be7b8bbcb7e4a77e2ef755988a  apache-1.3.31-i486-1.tgz
684626575e1c2a783b3d8d208876aab4  mod_ssl-2.8.17_1.3.31-i486-2.tgz
ad27d5f96281e11567184411b7c0720e  php-4.3.6-i486-2.tgz


Installation instructions:
+------------------------+

First, stop apache:

# apachectl stop

Next, upgrade the Apache package as root:
(if you're running -current, upgrade mod_ssl and php as well)

# upgradepkg apache-1.3.29-i486-2.tgz

Finally, restart apache:

# apachectl start

Or, if you're running a secure server with mod_ssl:

# apachectl startssl


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

+------------------------------------------------------------------------+
| To leave the slackware-security mailing list:                          |
+------------------------------------------------------------------------+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message:                                                     |
|                                                                        |
|   unsubscribe slackware-security                                       |
|                                                                        |
| You will get a confirmation message back containing instructions to    |
| complete the process.  Please do not reply to this email address.      |
+------------------------------------------------------------------------+

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAoq6BakRjwEAQIjMRArVdAKCUpK0yrttsmaiaxkwnyCMSMpjdygCdHgaK
WuRejVuF9XzjATed+VRlBYw=
=+cB4
-----END PGP SIGNATURE-----

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC