Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
BID:39538
Info
Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
| Bugtraq ID: | 39538 |
| Class: | Design Error |
| CVE: |
CVE-2010-1151 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2010 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | John Sullivan |
| Vulnerable: |
mod_auth_shadow mod_auth_shadow 2.2.11 mod_auth_shadow mod_auth_shadow 2.2.9 mod_auth_shadow mod_auth_shadow 2.2.8 mod_auth_shadow mod_auth_shadow 2.2.5 mod_auth_shadow mod_auth_shadow 2.2.4 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 |
| Not Vulnerable: | |
Discussion
Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
mod_auth_shadow is prone to a security-bypass vulnerability due to a race-condition error.
An attacker can exploit this vulnerability to bypass certain security restrictions and gain access to possibly sensitive or privileged information. Information obtained may be used in further attacks against the underlying system.
mod_auth_shadow is prone to a security-bypass vulnerability due to a race-condition error.
An attacker can exploit this vulnerability to bypass certain security restrictions and gain access to possibly sensitive or privileged information. Information obtained may be used in further attacks against the underlying system.
Exploit / POC
Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2009.1 x86_64
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.1
Mandriva Linux Mandrake 2010.0
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva apache-mod_auth_shadow-2.2-11.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva apache-mod_auth_shadow-2.2-4.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva apache-mod_auth_shadow-2.2-9.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva apache-mod_auth_shadow-2.2-4.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1
-
Mandriva apache-mod_auth_shadow-2.2-9.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva apache-mod_auth_shadow-2.2-11.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva apache-mod_auth_shadow-2.1-1.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva apache-mod_auth_shadow-2.1-1.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
Apache mod_auth_shadow Race Condition Security Bypass Vulnerability
References:
References:
- Bug 578168 - CVE-2010-1151 mod_auth_shadow: bad wait(2) call causes randomized a (Red Hat)
- Project Homepage (mod_auth_shadow)