Dave Carrigan Auth_LDAP Remote Format String Vulnerability
BID:16177
Info
Dave Carrigan Auth_LDAP Remote Format String Vulnerability
| Bugtraq ID: | 16177 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2006 12:00AM |
| Updated: | Aug 16 2006 11:40PM |
| Credit: | Seregorn <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Redhat Linux 7.3 i386 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Dave Carrigan auth_ldap 1.6 .0 Dave Carrigan auth_ldap 1.4 .X Dave Carrigan auth_ldap 1.3 .X Dave Carrigan auth_ldap 1.2 .X |
| Not Vulnerable: |
Dave Carrigan auth_ldap 1.6.1 |
Discussion
Dave Carrigan Auth_LDAP Remote Format String Vulnerability
Dave Carrigan's auth_ldap is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in the format-specifier of a formatted printing function.
This issue likely arises only if auth_ldap has been enabled and is used for user authentication.
This issue allows remote attackers to execute arbitrary machine code in the context of Apache webservers that use the affected module. This may facilitate the compromise of affected computers.
Dave Carrigan's auth_ldap is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in the format-specifier of a formatted printing function.
This issue likely arises only if auth_ldap has been enabled and is used for user authentication.
This issue allows remote attackers to execute arbitrary machine code in the context of Apache webservers that use the affected module. This may facilitate the compromise of affected computers.
Exploit / POC
Dave Carrigan Auth_LDAP Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Dave Carrigan Auth_LDAP Remote Format String Vulnerability
Solution:
Please see the referenced advisories for more information.
Dave Carrigan auth_ldap 1.2 .X
Dave Carrigan auth_ldap 1.3 .X
Dave Carrigan auth_ldap 1.4 .X
Dave Carrigan auth_ldap 1.6 .0
Solution:
Please see the referenced advisories for more information.
Dave Carrigan auth_ldap 1.2 .X
-
Dave Carrigan auth_ldap-1.6.1.tar.gz
http://www.rudedog.org/auth_ldap/auth_ldap-1.6.1.tar.gz
Dave Carrigan auth_ldap 1.3 .X
-
Dave Carrigan auth_ldap-1.6.1.tar.gz
http://www.rudedog.org/auth_ldap/auth_ldap-1.6.1.tar.gz
Dave Carrigan auth_ldap 1.4 .X
-
Dave Carrigan auth_ldap-1.6.1.tar.gz
http://www.rudedog.org/auth_ldap/auth_ldap-1.6.1.tar.gz
Dave Carrigan auth_ldap 1.6 .0
-
Dave Carrigan auth_ldap-1.6.1.tar.gz
http://www.rudedog.org/auth_ldap/auth_ldap-1.6.1.tar.gz -
Fedora Legacy auth_ldap-1.6.0-4.2.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/auth_ldap-1.6 .0-4.2.legacy.i386.rpm
References
Dave Carrigan Auth_LDAP Remote Format String Vulnerability
References:
References:
- auth_ldap Change Log (Dave Carrigan)
- Auth_ldap Home Page (Dave Carrigan)
- DSA-952-1 libapache-auth-ldap -- format string (Debian)
- RHSA-2006:0179-7 - auth_ldap security update (RedHat)
- Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple ([email protected])