Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
BID:28576
Info
Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
| Bugtraq ID: | 28576 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0555 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2008 12:00AM |
| Updated: | Apr 02 2008 09:09PM |
| Credit: | Alexander Klink from Cynops GmbH |
| Vulnerable: |
Apache-SSL Apache-SSL 1.3.34 +1.57 |
| Not Vulnerable: |
Apache-SSL Apache-SSL 1.3.41 +1.59 |
Discussion
Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
Apache-SSL is prone to a remote information-disclosure and privilege-escalation vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to obtain sensitive information or gain control of applications that use environment variables provided by Apache-SSL; this may lead to further attacks.
This issue affects Apache-SSL apache_1.3.34+ssl_1.57; other versions may also be vulnerable.
Apache-SSL is prone to a remote information-disclosure and privilege-escalation vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to obtain sensitive information or gain control of applications that use environment variables provided by Apache-SSL; this may lead to further attacks.
This issue affects Apache-SSL apache_1.3.34+ssl_1.57; other versions may also be vulnerable.
Exploit / POC
Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Apache-SSL Apache-SSL 1.3.34 +1.57
Solution:
The vendor has released fixes. Please see the references for more information.
Apache-SSL Apache-SSL 1.3.34 +1.57
-
Apache-SSL apache_1.3.41+ssl_1.59.tar.gz
ftp://ftp.ox.ac.uk/pub/crypto/SSL/Apache-SSL/apache_1.3.41+ssl_1.59.ta r.gz
References
Apache-SSL Environment Variable Information Disclosure and Privilege Escalation Vulnerability
References:
References:
- Apache-SSL Homepage (Apache-SSL)
- ANNOUNCE: Apache-SSL security release - apache_1.3.41+ssl_1.59 (Adam Laurie
) - advisory-cve-2008-0555.txt (Apache-SSL)