Cherokee HTTPD Insecure Privilege Release Vulnerability
BID:3771
Info
Cherokee HTTPD Insecure Privilege Release Vulnerability
| Bugtraq ID: | 3771 |
| Class: | Design Error |
| CVE: |
CVE-2001-1433 CVE-2001-1433 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2001 12:00AM |
| Updated: | Mar 19 2015 08:10AM |
| Credit: | This issue was initially publicized in a GOBBLES advisory on December 29th, 2001. |
| Vulnerable: |
Cherokee Cherokee HTTPD 0.2.6 Cherokee Cherokee HTTPD 0.2.5 Cherokee Cherokee HTTPD 0.2 Cherokee Cherokee HTTPD 0.1.6 Cherokee Cherokee HTTPD 0.1.5 Cherokee Cherokee HTTPD 0.1 |
| Not Vulnerable: |
Cherokee Cherokee HTTPD 0.2.7 |
Discussion
Cherokee HTTPD Insecure Privilege Release Vulnerability
Cherokee is a compact web server which provides fast delivery of web content. It is freely available and distributed under the GPL. It runs on Linux and other Unix systems.
Cherokee web server fails to drop root privileges after it binds to port 80.
While this vulnerability is not exploitable in and of itself, Cherokee web server is prone to a number of other issues which may result in a remote root compromise as a consequence of this issue. For example, BugTraq ID 3773 "Cherokee HTTPD Remote Command Execution Vulnerability" and BugTraq ID 3772 "Cherokee HTTPD Directory Traversal Vulnerability" may both be exploited to much greater effect as a result of this issue.
Cherokee is a compact web server which provides fast delivery of web content. It is freely available and distributed under the GPL. It runs on Linux and other Unix systems.
Cherokee web server fails to drop root privileges after it binds to port 80.
While this vulnerability is not exploitable in and of itself, Cherokee web server is prone to a number of other issues which may result in a remote root compromise as a consequence of this issue. For example, BugTraq ID 3773 "Cherokee HTTPD Remote Command Execution Vulnerability" and BugTraq ID 3772 "Cherokee HTTPD Directory Traversal Vulnerability" may both be exploited to much greater effect as a result of this issue.
Exploit / POC
Cherokee HTTPD Insecure Privilege Release Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Cherokee HTTPD Insecure Privilege Release Vulnerability
Solution:
The vendor has addressed this issue in Cherokee 0.2.7.
Cherokee Cherokee HTTPD 0.1
Cherokee Cherokee HTTPD 0.1.5
Cherokee Cherokee HTTPD 0.1.6
Cherokee Cherokee HTTPD 0.2
Cherokee Cherokee HTTPD 0.2.5
Cherokee Cherokee HTTPD 0.2.6
Solution:
The vendor has addressed this issue in Cherokee 0.2.7.
Cherokee Cherokee HTTPD 0.1
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
Cherokee Cherokee HTTPD 0.1.5
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
Cherokee Cherokee HTTPD 0.1.6
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
Cherokee Cherokee HTTPD 0.2
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
Cherokee Cherokee HTTPD 0.2.5
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
Cherokee Cherokee HTTPD 0.2.6
-
Cherokee Cherokee-0.2.7.tar.gz
http://aurora.esi.uem.es/~alo/cherokee/Cherokee-0.2.7.tar.gz
References
Cherokee HTTPD Insecure Privilege Release Vulnerability
References:
References:
- [VulnWatch] Remote Root Hole in Cherokee Webserver (VulnWatch)
- Cherokee Homepage (Cherokee)