[Full-Disclosure] Apache-SSL security advisory - apache_1.3.28+ssl_1.52 and prior

From: Adam Laurie (adam_at_algroup.co.uk)
Date: 02/06/04

  • Next message: Andrew: "RE: [Full-Disclosure] Gee Why don't you teach then! Help out the community."
    To: apache-ssl@lists.aldigital.co.uk, apache-sslannounce@lists.aldigital.co.uk, full-disclosure@lists.netsys.com, bugtraq@securityfocus.com
    Date: Fri, 06 Feb 2004 12:05:24 +0000
    
    

    Apache-SSL optional client certificate vulnerability
    ----------------------------------------------------

    Synopsis
    --------

    If configured with SSLVerifyClient set to 1 or 3 (client certificates
    optional) and SSLFakeBasicAuth, Apache-SSL 1.3.28+1.52 and all earlier
    versions would permit a client to use real basic authentication to
    forge a client certificate.

    All the attacker needed is the "one-line DN" of a valid user, as used
    by faked basic auth in Apache-SSL, and the fixed password ("password"
    by default).

    Fix

    ---
    Install Apache-SSL 1.3.29+1.53 from the usual places (see
    http://www.apache-ssl.org/).
    Credits
    -------
    This vulnerability was found and reported by Wietse Venema.
    cheers,
    Adam
    -- 
    Adam Laurie                   Tel: +44 (20) 8742 0755
    A.L. Digital Ltd.             Fax: +44 (20) 8742 5995
    The Stores                    http://www.thebunker.net
    2 Bath Road                   http://www.aldigital.co.uk
    London W4 1LT                 mailto:adam@algroup.co.uk
    UNITED KINGDOM                PGP key on keyservers
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Andrew: "RE: [Full-Disclosure] Gee Why don't you teach then! Help out the community."

    Relevant Pages


    Loading