NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
BID:3375
Info
NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
| Bugtraq ID: | 3375 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2001 12:00AM |
| Updated: | Sep 28 2001 12:00AM |
| Credit: | This vulnerability was discovered and announced to the Bugtraq mailing list by Nobuo Miwa <[email protected]> on September 28, 2001. |
| Vulnerable: |
Network Associates PGP Keyserver 7.0.1 Network Associates PGP Keyserver 7.0 |
| Not Vulnerable: | |
Discussion
NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
PGP Keyserver is a commercially available encryption software package from Network Associates. It is designed as a PGP public key management system, with features such as LDAP.
A problem in the PGP key server makes it possible for remote users to gain administrative access to the interface. Typical administration of the interface passes commands through the http://www.example.com/keyserver/cgi-bin/console.exe?page_size=... and http://www.example.com/keyserver/cgi-bin/cs.exe?action=... commands. These commands, however, may be directly accessed without authentication from the user.
This makes it possible for a remote user to deny service to a legitimate user of the system. This could also potentially result in a malicious user replacing PGP Keys with malicious keys, and gaining access to sensitive information.
PGP Keyserver is a commercially available encryption software package from Network Associates. It is designed as a PGP public key management system, with features such as LDAP.
A problem in the PGP key server makes it possible for remote users to gain administrative access to the interface. Typical administration of the interface passes commands through the http://www.example.com/keyserver/cgi-bin/console.exe?page_size=... and http://www.example.com/keyserver/cgi-bin/cs.exe?action=... commands. These commands, however, may be directly accessed without authentication from the user.
This makes it possible for a remote user to deny service to a legitimate user of the system. This could also potentially result in a malicious user replacing PGP Keys with malicious keys, and gaining access to sensitive information.
Exploit / POC
NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
References
NAI PGP Keyserver Web Administration Interface Authentication Bypassing Vulnerability
References:
References: