Apache mod_python Output Filter Mode Information Disclosure Vulnerability
BID:22849
Info
Apache mod_python Output Filter Mode Information Disclosure Vulnerability
| Bugtraq ID: | 22849 |
| Class: | Design Error |
| CVE: |
CVE-2004-2680 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2007 12:00AM |
| Updated: | Mar 08 2007 04:55AM |
| Credit: | Miles Egan is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 rPath rPath Linux 1 Apache mod_python 3.1.4 Apache mod_python 3.1.3 Apache mod_python 3.0.4 Apache mod_python 3.0.3 |
| Not Vulnerable: |
Apache mod_python 3.2.8 Apache mod_python 3.2.7 |
Discussion
Apache mod_python Output Filter Mode Information Disclosure Vulnerability
The Apache mod_python module is prone to an information-disclosure vulnerability because of a design error in the affected application.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
The Apache mod_python module is prone to an information-disclosure vulnerability because of a design error in the affected application.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
Exploit / POC
Apache mod_python Output Filter Mode Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Apache mod_python Output Filter Mode Information Disclosure Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Apache mod_python Output Filter Mode Information Disclosure Vulnerability
References:
References:
- Apache mod_python Product Page (Apache Software Foundation)
- rPSA-2007-0051-1 mod_python (rPath Update Announcements
) - rPath Security Advisory: 2007-0051-1 (rPath)