MacOS X Client Apache File Protection Bypass Vulnerability
BID:2852
Info
MacOS X Client Apache File Protection Bypass Vulnerability
| Bugtraq ID: | 2852 |
| Class: | Design Error |
| CVE: |
CVE-2001-0766 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq by Stefan Arentz <[email protected]> on June 10th, 2001. |
| Vulnerable: |
Apache Apache 1.3.14 Mac |
| Not Vulnerable: | |
Discussion
MacOS X Client Apache File Protection Bypass Vulnerability
A vulnerability exists when Apache webserver is used with Mac OS X Client.
The standard filesystem for Mac OS X is HFS+. HFS+ is case insensitive while Apache's filtering is case sensitive. The result is that Apache will filter all file requests that match filters exactly (including case), but it will not filter requests made with mixed or upper case characters. Since HFS+ is case insensitive, these requests will result in the "filtered" files being disclosed.
The impact is that arbitrary privileged files may be disclosed to unprivileged remote users.
A vulnerability exists when Apache webserver is used with Mac OS X Client.
The standard filesystem for Mac OS X is HFS+. HFS+ is case insensitive while Apache's filtering is case sensitive. The result is that Apache will filter all file requests that match filters exactly (including case), but it will not filter requests made with mixed or upper case characters. Since HFS+ is case insensitive, these requests will result in the "filtered" files being disclosed.
The impact is that arbitrary privileged files may be disclosed to unprivileged remote users.
Solution / Fix
MacOS X Client Apache File Protection Bypass Vulnerability
References
MacOS X Client Apache File Protection Bypass Vulnerability
References:
References: