Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
BID:11574
Info
Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
| Bugtraq ID: | 11574 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2004 12:00AM |
| Updated: | Nov 01 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Florian Schilhabel from the Gentoo Linux Security Audit Team. |
| Vulnerable: |
Cherokee-Project Cherokee HTTPD 0.4.17 Cherokee-Project Cherokee HTTPD 0.4.8 Cherokee-Project Cherokee HTTPD 0.4.7 Cherokee-Project Cherokee HTTPD 0.4.6 Cherokee-Project Cherokee HTTPD 0.2.7 Cherokee-Project Cherokee HTTPD 0.2.6 Cherokee-Project Cherokee HTTPD 0.2.5 Cherokee-Project Cherokee HTTPD 0.2 Cherokee-Project Cherokee HTTPD 0.1.6 Cherokee-Project Cherokee HTTPD 0.1.5 Cherokee-Project Cherokee HTTPD 0.1 |
| Not Vulnerable: | |
Discussion
Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
It is reported that Cherokee is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
A remote attacker may exploit this vulnerability to execute arbitrary code in the context of the affected service.
It is reported that Cherokee is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
A remote attacker may exploit this vulnerability to execute arbitrary code in the context of the affected service.
Exploit / POC
Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200411-02) and an updated eBuild to address this issue. Gentoo recommends that users invoke the following sequence of commands in order to apply the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-servers/cherokee-0.4.17.1"
Solution:
Gentoo has released an advisory (GLSA 200411-02) and an updated eBuild to address this issue. Gentoo recommends that users invoke the following sequence of commands in order to apply the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-servers/cherokee-0.4.17.1"
References
Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability
References:
References:
- Cherokee Homepage (Cherokee)