CVE-2005-2963
Summary
| CVE | CVE-2005-2963 |
|---|---|
| State | PUBLISHED |
| Assigner | debian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-13 21:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.0 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.1 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.2 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.3 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.4 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 1.5 | All | All | All |
| Application | Mod Auth Shadow | Mod Auth Shadow | 2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Mod_Auth_Shadow Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Secunia - Advisories - Mandriva update for apache-mod_auth_shadow | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| #323789 - Turns itself on when require group is used - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Debian -- Security Information -- DSA-844-1 mod-auth-shadow | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| Debian update for mod-auth-shadow - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apache mod_auth_shadow Module "require group" Incorrect Authentication - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/19863 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| frontal1.mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | frontal1.mandriva.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.