Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
BID:6029
Info
Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
| Bugtraq ID: | 6029 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1157 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery credited to Joe Orton. |
| Vulnerable: |
Sun Cobalt RaQ XTR Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 Sun Cobalt Qube 3 OpenPKG OpenPKG 1.1 OpenPKG OpenPKG 1.0 OpenPKG OpenPKG Current mod_ssl mod_ssl 2.8.9 mod_ssl mod_ssl 2.4 .10 Mandriva Linux Mandrake 9.0 Mandriva Linux Mandrake 8.2 ppc Mandriva Linux Mandrake 8.2 Mandriva Linux Mandrake 8.1 ia64 Mandriva Linux Mandrake 8.1 Mandriva Linux Mandrake 8.0 ppc Mandriva Linux Mandrake 8.0 Mandriva Linux Mandrake 7.2 MandrakeSoft Single Network Firewall 7.2 EnGarde Secure Linux 1.0.1 Apache Apache 2.0.40 Apache Apache 1.3.23 Apache Apache 1.3.22 |
| Not Vulnerable: | |
Discussion
Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
A vulnerability has been discovered in the mod_ssl module, for Apache.
It should be noted that the existance of this vulnerability is limited to configurations with both the 'UseCanonicalName' option turned off and wildcard DNS enabled.
It has been reported that Apache v1.x, when using the mod_ssl module will return an unescaped server name in response to HTTP requests on SSL ports.
If all of these circumstances are met, an attacker may be able to exploit this issue via a malicious link containing arbitrary HTML and script code as part of the hostname. When the malicious link is clicked by an unsuspecting user, the attacker-supplied HTML and script code will be executed by their web client. This will occur because the server will echo back the malicious hostname supplied in the client's request, without sufficiently escaping HTML and script code.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
A vulnerability has been discovered in the mod_ssl module, for Apache.
It should be noted that the existance of this vulnerability is limited to configurations with both the 'UseCanonicalName' option turned off and wildcard DNS enabled.
It has been reported that Apache v1.x, when using the mod_ssl module will return an unescaped server name in response to HTTP requests on SSL ports.
If all of these circumstances are met, an attacker may be able to exploit this issue via a malicious link containing arbitrary HTML and script code as part of the hostname. When the malicious link is clicked by an unsuspecting user, the attacker-supplied HTML and script code will be executed by their web client. This will occur because the server will echo back the malicious hostname supplied in the client's request, without sufficiently escaping HTML and script code.
Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.
Exploit / POC
Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
Solution:
Debian has released an advisory containing fixes.
Conectiva Linux has released a security advisory containing fixes. Further information can be obtained from the referenced advisory.
RedHat has released a security advisory (RHSA-2002:222-21) which contains fixes that address this issue. Further details can be obtained from the referenced advisory.
Fixes:
OpenPKG OpenPKG Current
Sun Cobalt RaQ 550
Sun Cobalt Qube 3
Sun Cobalt RaQ 4
Sun Cobalt RaQ XTR
OpenPKG OpenPKG 1.0
EnGarde Secure Linux 1.0.1
OpenPKG OpenPKG 1.1
Apache Apache 1.3.22
Apache Apache 1.3.23
Apache Apache 2.0.40
MandrakeSoft Single Network Firewall 7.2
Mandriva Linux Mandrake 7.2
Mandriva Linux Mandrake 8.0 ppc
Mandriva Linux Mandrake 8.0
Mandriva Linux Mandrake 8.1 ia64
Mandriva Linux Mandrake 8.1
Mandriva Linux Mandrake 8.2 ppc
Mandriva Linux Mandrake 8.2
Mandriva Linux Mandrake 9.0
Solution:
Debian has released an advisory containing fixes.
Conectiva Linux has released a security advisory containing fixes. Further information can be obtained from the referenced advisory.
RedHat has released a security advisory (RHSA-2002:222-21) which contains fixes that address this issue. Further details can be obtained from the referenced advisory.
Fixes:
OpenPKG OpenPKG Current
-
OpenPKG apache-1.3.27-20021023.src.rpm
ftp://ftp.openpkg.org/current/SRC/apache-1.3.27-20021023.src.rpm
Sun Cobalt RaQ 550
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg
Sun Cobalt Qube 3
-
Sun Qube3-All-Security-4.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/qube3/ml/Qube3-All-Security-4.0 .1-16343.pkg
Sun Cobalt RaQ 4
-
Sun RaQ4-All-Security-2.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq4/eng/RaQ4-All-Security-2.0. 1-16343.pkg
Sun Cobalt RaQ XTR
-
Sun RaQ550-All-Security-0.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raq550/all/RaQ550-All-Security- 0.0.1-16343.pkg -
Sun RaQXTR-All-Security-1.0.1-16343.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16343.pkg
OpenPKG OpenPKG 1.0
-
OpenPKG apache-1.3.22-1.0.6.src.rpm
ftp://ftp.openpkg.org/release/1.0/UPD/apache-1.3.22-1.0.6.src.rpm
EnGarde Secure Linux 1.0.1
-
EnGarde Secure Linux apache-1.3.27-1.0.33.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i386/apache-1.3. 27-1.0.33.i386.rpm -
EnGarde Secure Linux apache-1.3.27-1.0.33.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/stable/updates/i686/apache-1.3. 27-1.0.33.i686.rpm
OpenPKG OpenPKG 1.1
-
OpenPKG apache-1.3.26-1.1.2.src.rpm
ftp://ftp.openpkg.org/release/1.1/UPD/apache-1.3.26-1.1.2.src.rpm
Apache Apache 1.3.22
-
OpenPKG apache-1.3.22-1.0.6.src.rpm
ftp://ftp.openpkg.org/release/1.0/UPD/apache-1.3.22-1.0.6.src.rpm -
RedHat apache-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-1.3.27-1.6.2.alpha.rpm -
RedHat apache-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-1.3.27-1.6.2.i386.rpm -
RedHat apache-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-1.3.27-1.6.2.sparc.rpm -
RedHat apache-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-1.3.27-1.7.1.alpha.rpm -
RedHat apache-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-1.3.27-1.7.1.i386.rpm -
RedHat apache-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-1.3.27-1.7.1.ia64.rpm -
RedHat apache-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-1.3.27-1.7.2.i386.rpm -
RedHat apache-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-1.3.27-1.7.2.ia64.rpm -
RedHat apache-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-1.3.27-2.i386.rpm -
RedHat apache-devel-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-devel-1.3.27-1.6.2.alp ha.rpm -
RedHat apache-devel-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-devel-1.3.27-1.6.2.i386 .rpm -
RedHat apache-devel-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-devel-1.3.27-1.6.2.spa rc.rpm -
RedHat apache-devel-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-devel-1.3.27-1.7.1.alp ha.rpm -
RedHat apache-devel-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-devel-1.3.27-1.7.1.i386 .rpm -
RedHat apache-devel-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-devel-1.3.27-1.7.1.ia64 .rpm -
RedHat apache-devel-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-devel-1.3.27-1.7.2.i386 .rpm -
RedHat apache-devel-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-devel-1.3.27-1.7.2.ia64 .rpm -
RedHat apache-devel-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-devel-1.3.27-2.i386.rpm -
RedHat apache-manual-1.3.27-1.6.2.alpha.rpm
ftp://updates.redhat.com/6.2/en/os/alpha/apache-manual-1.3.27-1.6.2.al pha.rpm -
RedHat apache-manual-1.3.27-1.6.2.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/apache-manual-1.3.27-1.6.2.i38 6.rpm -
RedHat apache-manual-1.3.27-1.6.2.sparc.rpm
ftp://updates.redhat.com/6.2/en/os/sparc/apache-manual-1.3.27-1.6.2.sp arc.rpm -
RedHat apache-manual-1.3.27-1.7.1.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/apache-manual-1.3.27-1.7.1.al pha.rpm -
RedHat apache-manual-1.3.27-1.7.1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/apache-manual-1.3.27-1.7.1.i38 6.rpm -
RedHat apache-manual-1.3.27-1.7.1.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/apache-manual-1.3.27-1.7.1.ia6 4.rpm -
RedHat apache-manual-1.3.27-1.7.2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/apache-manual-1.3.27-1.7.2.i38 6.rpm -
RedHat apache-manual-1.3.27-1.7.2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/apache-manual-1.3.27-1.7.2.ia6 4.rpm -
RedHat apache-manual-1.3.27-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/apache-manual-1.3.27-2.i386.rp m -
RedHat mod_ssl-2.0.40-11.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.i386.rpm -
RedHat mod_ssl-2.8.12-1.7.alpha.rpm
ftp://updates.redhat.com/7.0/en/os/alpha/mod_ssl-2.8.12-1.7.alpha.rpm -
RedHat mod_ssl-2.8.12-1.7.alpha.rpm
ftp://updates.redhat.com/7.1/en/os/alpha/mod_ssl-2.8.12-1.7.alpha.rpm -
RedHat mod_ssl-2.8.12-1.7.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/mod_ssl-2.8.12-1.7.i386.rpm -
RedHat mod_ssl-2.8.12-1.7.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/mod_ssl-2.8.12-1.7.i386.rpm -
RedHat mod_ssl-2.8.12-1.7.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/mod_ssl-2.8.12-1.7.ia64.rpm -
RedHat mod_ssl-2.8.12-2.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/mod_ssl-2.8.12-2.i386.rpm -
RedHat mod_ssl-2.8.12-2.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/mod_ssl-2.8.12-2.ia64.rpm
Apache Apache 1.3.23
-
RedHat mod_ssl-2.8.12-2.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/mod_ssl-2.8.12-2.i386.rpm
Apache Apache 2.0.40
-
RedHat mod_ssl-2.0.40-11.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.i386.rpm
MandrakeSoft Single Network Firewall 7.2
-
MandrakeSoft mod_ssl-2.8.4-5.2mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/snf7.2/RPMS/mod_ssl-2. 8.4-5.2mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.4-5.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/snf7.2/SRPMS/mod_ssl-2 .8.4-5.2mdk.src.rpm
Mandriva Linux Mandrake 7.2
-
MandrakeSoft mod_ssl-2.8.5-3.2mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/7.2/RPMS/mod_ssl-2.8.5 -3.2mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.5-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/7.2/SRPMS/mod_ssl-2.8. 5-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.0 ppc
-
MandrakeSoft mod_ssl-2.8.5-3.2mdk.ppc.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ppc/8.0/RPMS/mod_ssl-2 .8.5-3.2mdk.ppc.rpm -
MandrakeSoft mod_ssl-2.8.5-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ppc/8.0/SRPMS/mod_ssl- 2.8.5-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.0
-
MandrakeSoft mod_ssl-2.8.5-3.2mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.0/RPMS/mod_ssl-2.8.5 -3.2mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.5-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.0/SRPMS/mod_ssl-2.8. 5-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.1 ia64
-
MandrakeSoft mod_ssl-2.8.5-3.2mdk.ia64.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ia64/8.1/RPMS/mod_ssl- 2.8.5-3.2mdk.ia64.rpm -
MandrakeSoft mod_ssl-2.8.5-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ia64/8.1/SRPMS/mod_ssl -2.8.5-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.1
-
MandrakeSoft mod_ssl-2.8.5-3.2mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.1/RPMS/mod_ssl-2.8.5 -3.2mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.5-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.1/SRPMS/mod_ssl-2.8. 5-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.2 ppc
-
MandrakeSoft mod_ssl-2.8.7-3.2mdk.ppc.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ppc/8.2/RPMS/mod_ssl-2 .8.7-3.2mdk.ppc.rpm -
MandrakeSoft mod_ssl-2.8.7-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/ppc/8.2/SRPMS/mod_ssl- 2.8.7-3.2mdk.src.rpm
Mandriva Linux Mandrake 8.2
-
MandrakeSoft mod_ssl-2.8.7-3.2mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.2/RPMS/mod_ssl-2.8.7 -3.2mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.7-3.2mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/8.2/SRPMS/mod_ssl-2.8. 7-3.2mdk.src.rpm
Mandriva Linux Mandrake 9.0
-
MandrakeSoft mod_ssl-2.8.10-5.1mdk.i586.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/9.0/RPMS/mod_ssl-2.8.1 0-5.1mdk.i586.rpm -
MandrakeSoft mod_ssl-2.8.10-5.1mdk.src.rpm
ftp://ftp.planetmirror.com/pub/Mandrake/updates/9.0/SRPMS/mod_ssl-2.8. 10-5.1mdk.src.rpm
References
Mod_SSL Wildcard DNS Cross Site Scripting Vulnerability
References:
References:
- mod_ssl Homepage (mod_ssl Project)