PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
BID:24034
Info
PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
| Bugtraq ID: | 24034 |
| Class: | Design Error |
| CVE: |
CVE-2007-2510 CVE-2007-2728 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2007 12:00AM |
| Updated: | Mar 19 2015 08:35AM |
| Credit: | Stefan Essar is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc PHP PHP 5.2.2 PHP PHP 5.2.1 PHP PHP 5.1.6 PHP PHP 5.1.5 PHP PHP 5.1.4 PHP PHP 5.1.3 -RC1 PHP PHP 5.1.3 PHP PHP 5.1.2 PHP PHP 5.1.1 PHP PHP 5.1 PHP PHP 5.0.5 PHP PHP 5.0.4 PHP PHP 5.0.3 PHP PHP 5.0.2 PHP PHP 5.0.1 PHP PHP 5.0 candidate 3 PHP PHP 5.0 candidate 2 PHP PHP 5.0 candidate 1 PHP PHP 5.0 .0 PHP PHP 4.4.7 PHP PHP 4.4.6 PHP PHP 4.4.5 PHP PHP 4.4.4 PHP PHP 4.4.3 PHP PHP 4.4.2 PHP PHP 4.4.1 PHP PHP 4.4 .0 PHP PHP 4.3.11 PHP PHP 4.3.10 PHP PHP 4.3.9 PHP PHP 4.3.8 PHP PHP 4.3.7 PHP PHP 4.3.6 PHP PHP 4.3.5 PHP PHP 4.3.4 PHP PHP 4.3.3 PHP PHP 4.3.2 PHP PHP 4.3.1 PHP PHP 4.3 PHP PHP 4.2.3 PHP PHP 4.2.2 PHP PHP 4.2.1 PHP PHP 4.2 .0 PHP PHP 4.2 -dev PHP PHP 4.1.2 PHP PHP 4.1.1 PHP PHP 4.1 .0 PHP PHP 4.0.7 RC3 PHP PHP 4.0.7 RC2 PHP PHP 4.0.7 RC1 PHP PHP 4.0.7 PHP PHP 4.0.6 PHP PHP 4.0.5 PHP PHP 4.0.4 PHP PHP 4.0.3 pl1 PHP PHP 4.0.3 PHP PHP 4.0.2 PHP PHP 4.0.1 pl2 PHP PHP 4.0.1 pl1 PHP PHP 4.0.1 PHP PHP 5.2 |
| Not Vulnerable: | |
Discussion
PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
PHP Soap Engine is prone to an authentication weakness.
Successfully exploiting this issue would allow an attacker to obtain information about the nonce used for the digest authentication. Information obtained may allow the attacker to bypass certain security restrictions and potentially gain unauthorized access to the affected application.
PHP Soap Engine is prone to an authentication weakness.
Successfully exploiting this issue would allow an attacker to obtain information about the nonce used for the digest authentication. Information obtained may allow the attacker to bypass certain security restrictions and potentially gain unauthorized access to the affected application.
Exploit / POC
PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
An attacker can exploit this issue by using brute-force techniques to guess the value of the nonce.
An attacker can exploit this issue by using brute-force techniques to guess the value of the nonce.
Solution / Fix
PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
Solution:
The vendor released an update to address this issue. The update is available through the CVS repository. Please see the references for more information.
Solution:
The vendor released an update to address this issue. The update is available through the CVS repository. Please see the references for more information.
References
PHP Soap Engine Make_HTTP_Soap_Request Weak Nonce HTTP Authentication Weakness
References:
References:
- PHP Homepage (PHP)
- USN-462-1 - php5 vulnerabilities (Ubuntu)
- Watching the PHP CVS (Stefan Essar )
- SUSE Security Announcement SUSE-SA:2007:044 (SUSE)