Apache Satisfy Directive Access Control Bypass Vulnerability
BID:11239
Info
Apache Satisfy Directive Access Control Bypass Vulnerability
| Bugtraq ID: | 11239 |
| Class: | Design Error |
| CVE: |
CVE-2004-0811 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | The discoverer of this issue is not known at the moment. |
| Vulnerable: |
HP Tru64 UNIX Compaq Secure Web Server 6.3 HP Tru64 UNIX Compaq Secure Web Server 5.9.2 HP Tru64 UNIX Compaq Secure Web Server 5.9.1 HP Tru64 UNIX Compaq Secure Web Server 5.8.2 HP Tru64 UNIX Compaq Secure Web Server 5.8.1 HP Tru64 UNIX Compaq Secure Web Server 5.1 A HP Tru64 UNIX Compaq Secure Web Server 5.1 HP Tru64 UNIX Compaq Secure Web Server 5.0 A HP Tru64 UNIX Compaq Secure Web Server 4.0 G HP Tru64 UNIX Compaq Secure Web Server 4.0 F HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Apache Apache 2.0.51 |
| Not Vulnerable: |
HP Tru64 UNIX Compaq Secure Web Server 6.3.2 a Apache Apache 2.0.52 |
Discussion
Apache Satisfy Directive Access Control Bypass Vulnerability
Apache Web Server is reportedly affected by an access control bypass vulnerability. This issue presents itself due to an unspecified error in the merging of the 'Satisfy' directive. As a result, a remote attacker may bypass access controls and gain unauthorized access to restricted resources.
It is reported that this issue only affects Apache 2.0.51.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
Apache Web Server is reportedly affected by an access control bypass vulnerability. This issue presents itself due to an unspecified error in the merging of the 'Satisfy' directive. As a result, a remote attacker may bypass access controls and gain unauthorized access to restricted resources.
It is reported that this issue only affects Apache 2.0.51.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
Exploit / POC
Apache Satisfy Directive Access Control Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Apache Satisfy Directive Access Control Bypass Vulnerability
Solution:
HP has released an advisory (HPSBGN01091) and an update to fix this vulnerability and other vulnerabilities in Secure Web Server for Tru64 UNIX; the Secure Web Server product is based on Apache.
Trustix Linux has released an advisory (TSLSA-2004-0049) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory (GLSA 200409-33) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems:
emerge sync
emerge -pv ">=net-www/apache-2.0.51-r1"
emerge ">=net-www/apache-2.0.51-r1"
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released version 2.0.52 to address this issue:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
Apache Apache 2.0.51
HP Tru64 UNIX Compaq Secure Web Server 4.0 F
HP Tru64 UNIX Compaq Secure Web Server 4.0 G
HP Tru64 UNIX Compaq Secure Web Server 5.0 A
HP Tru64 UNIX Compaq Secure Web Server 5.1 A
HP Tru64 UNIX Compaq Secure Web Server 5.1
HP Tru64 UNIX Compaq Secure Web Server 5.8.1
HP Tru64 UNIX Compaq Secure Web Server 5.8.2
HP Tru64 UNIX Compaq Secure Web Server 5.9.1
HP Tru64 UNIX Compaq Secure Web Server 5.9.2
HP Tru64 UNIX Compaq Secure Web Server 6.3
Solution:
HP has released an advisory (HPSBGN01091) and an update to fix this vulnerability and other vulnerabilities in Secure Web Server for Tru64 UNIX; the Secure Web Server product is based on Apache.
Trustix Linux has released an advisory (TSLSA-2004-0049) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Gentoo has released advisory (GLSA 200409-33) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their systems:
emerge sync
emerge -pv ">=net-www/apache-2.0.51-r1"
emerge ">=net-www/apache-2.0.51-r1"
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released version 2.0.52 to address this issue:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
Apache Apache 2.0.51
-
Apache Software Foundation httpd-2.0.52.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.52.tar.gz
HP Tru64 UNIX Compaq Secure Web Server 4.0 F
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 4.0 G
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.0 A
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.1 A
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.1
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.8.1
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.8.2
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.9.1
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 5.9.2
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
HP Tru64 UNIX Compaq Secure Web Server 6.3
-
HP Secure Web Server 6.3.2a for Tru64 UNIX
http://h30097.www3.hp.com/internet/download.htm
References
Apache Satisfy Directive Access Control Bypass Vulnerability
References:
References:
- Apache 2.0.x Latest Release Information Page (Apache Software Foundation)
- Apache Homepage (Apache Software Foundation)