[Full-Disclosure] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior
From: Adam Laurie (adam_at_algroup.co.uk)
Date: 02/06/04
- Previous message: Ishikodzume: "Re: [Full-Disclosure] Gee Why don't you teach then! Help out the community."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: apache-ssl@lists.aldigital.co.uk, apache-sslannounce@lists.aldigital.co.uk, full-disclosure@lists.netsys.com, bugtraq@securityfocus.com Date: Fri, 06 Feb 2004 12:05:24 +0000
Apache-SSL optional client certificate vulnerability
----------------------------------------------------
Synopsis
--------
If configured with SSLVerifyClient set to 1 or 3 (client certificates
optional) and SSLFakeBasicAuth, Apache-SSL 1.3.28+1.52 and all earlier
versions would permit a client to use real basic authentication to
forge a client certificate.
All the attacker needed is the "one-line DN" of a valid user, as used
by faked basic auth in Apache-SSL, and the fixed password ("password"
by default).
Fix
--- Install Apache-SSL 1.3.29+1.53 from the usual places (see http://www.apache-ssl.org/). Credits ------- This vulnerability was found and reported by Wietse Venema. cheers, Adam -- Adam Laurie Tel: +44 (20) 8742 0755 A.L. Digital Ltd. Fax: +44 (20) 8742 5995 The Stores http://www.thebunker.net 2 Bath Road http://www.aldigital.co.uk London W4 1LT mailto:adam@algroup.co.uk UNITED KINGDOM PGP key on keyservers _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
- Previous message: Ishikodzume: "Re: [Full-Disclosure] Gee Why don't you teach then! Help out the community."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
Loading