Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
BID:3255
Info
Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
| Bugtraq ID: | 3255 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq in a RUS-CERT Advisory on August 29th, 2001. |
| Vulnerable: |
Vivek Khera mod_auth_mysql 1.9 |
| Not Vulnerable: |
Zeev Suraski mod_auth_mysql 2.20 Vivek Khera mod_auth_mysql 1.10 |
Discussion
Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
'mod_auth_mysql' is an authentication module required by Apache server to make use of database-based authentication using MySQL.
This authentication module for Apache is prone to a vulnerability which will allow SQL queries to be manipulated via a HTTP request. Data that is included in SQL query strings is not adequately sanitized. It may be possible for malicious users to modify the structure of SQL queries.
It should be noted that this module does not allow for multiple queries to be sent. This effectively restricts exploitation to the query the module is already performing.
This issue allows the user to access resources that would normally be restricted, which may in turn provide an opportunity for the attacker to exploit other vulnerabilities that exist in the server.
It should be noted that Zeev Suraski's mod_auth_mysql 2.20 is not vulnerable.
'mod_auth_mysql' is an authentication module required by Apache server to make use of database-based authentication using MySQL.
This authentication module for Apache is prone to a vulnerability which will allow SQL queries to be manipulated via a HTTP request. Data that is included in SQL query strings is not adequately sanitized. It may be possible for malicious users to modify the structure of SQL queries.
It should be noted that this module does not allow for multiple queries to be sent. This effectively restricts exploitation to the query the module is already performing.
This issue allows the user to access resources that would normally be restricted, which may in turn provide an opportunity for the attacker to exploit other vulnerabilities that exist in the server.
It should be noted that Zeev Suraski's mod_auth_mysql 2.20 is not vulnerable.
Exploit / POC
Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache mod_auth_mysql Remote SQL Query Manipulation Vulnerability
Solution:
The vendor has addressed this issue in a new release.
Conectiva has also released upgrades which fix this and other issues.
SuSE has released upgrades which fix this issue.
Vivek Khera mod_auth_mysql 1.9
Solution:
The vendor has addressed this issue in a new release.
Conectiva has also released upgrades which fix this and other issues.
SuSE has released upgrades which fix this issue.
Vivek Khera mod_auth_mysql 1.9
-
Conectiva 4.1 mod_auth_mysql-1.11-1U41_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/mod_auth_mysql-1.11-1U41_ 1cl.i386.rpm -
Conectiva 4.2 mod_auth_mysql-1.11-1U42_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/mod_auth_mysql-1.11-1U42_ 1cl.i386.rpm -
Conectiva 5.0 mod_auth_mysql-1.11-1U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/mod_auth_mysql-1.11-1U50_ 1cl.i386.rpm -
Conectiva 5.1 mod_auth_mysql-1.11-1U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/mod_auth_mysql-1.11-1U51_ 1cl.i386.rpm -
Conectiva 6.0 mod_auth_mysql-1.11-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/mod_auth_mysql-1.11-1U60_ 1cl.i386.rpm -
Conectiva 7.0 mod_auth_mysql-1.11-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/mod_auth_mysql-1.11-1U70_ 1cl.i386.rpm -
SuSE 7.1 Alpha apache-contrib-1.0.8-23.alpha.rpm
ftp://ftp.suse.com/pub/suse/axp/update/7.1/n2/apache-contrib-1.0.8-23. alpha.rpm -
SuSE 7.1 i386 apache-contrib-1.0.8-35.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.1/n2/apache-contrib-1.0.8-35 .i386.rpm -
SuSE 7.1 PPC apache-contrib-1.0.8-22.ppc.rpm
ftp://ftp.suse.com/pub/suse/ppc/update/7.1/n2/apache-contrib-1.0.8-22. ppc.rpm -
SuSE 7.1 SPARC apache-contrib-1.0.8-22.sparc.rpm
ftp://ftp.suse.com/pub/suse/sparc/update/7.1/n2/apache-contrib-1.0.8-2 2.sparc.rpm -
SuSE 7.2 i386 apache-contrib-1.0.9-94.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n2/apache-contrib-1.0.9-94 .i386.rpm -
Vivek Khera mod_auth_mysql 1.10
ftp://ftp.kcilink.com/pub/