Apache Web Server MIME Boundary Information Disclosure Vulnerability
BID:6943
Info
Apache Web Server MIME Boundary Information Disclosure Vulnerability
| Bugtraq ID: | 6943 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2003 12:00AM |
| Updated: | Feb 25 2003 12:00AM |
| Credit: | This issue was reported by OpenBSD on their errata page. |
| Vulnerable: |
OpenBSD OpenBSD 3.2 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 |
| Not Vulnerable: | |
Discussion
Apache Web Server MIME Boundary Information Disclosure Vulnerability
A vulnerability has been discovered in the Apache web server that may result in the disclosure of sensitive information. Specifically, sensitive process information is used within generated MIME message boundaries.
Access to this information may aid an attacker in launching attacks further attacks against target services.
OpenBSD has released a patch that addresses this issue. MIME boundaries are now generated by the server using BASE64 encoded random numbers.
A vulnerability has been discovered in the Apache web server that may result in the disclosure of sensitive information. Specifically, sensitive process information is used within generated MIME message boundaries.
Access to this information may aid an attacker in launching attacks further attacks against target services.
OpenBSD has released a patch that addresses this issue. MIME boundaries are now generated by the server using BASE64 encoded random numbers.
Exploit / POC
Apache Web Server MIME Boundary Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Apache Web Server MIME Boundary Information Disclosure Vulnerability
Solution:
OpenBSD has released a patch to address this issue.
OpenBSD OpenBSD 3.2
Solution:
OpenBSD has released a patch to address this issue.
OpenBSD OpenBSD 3.2
-
OpenBSD 008_httpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/008_httpd.patch
References
Apache Web Server MIME Boundary Information Disclosure Vulnerability
References:
References:
- OpenBSD 3.2 release errata & patch list (OpenBSD)