Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
BID:8926
Info
Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
| Bugtraq ID: | 8926 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0789 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | This vulnerability was reported by Apache. |
| Vulnerable: |
Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.48 |
Discussion
Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
Apache has reported a vulnerability in the mod_cgid module when the threaded MPM is used. The problem is said to occur due to mishandling of CGI redirect paths. The condition may potentially cause CGI data to inadvertently be sent to the wrong client. Depending on the context of the data being redirected, this could potentially expose sensitive information or incorrectly grant unauthorized access.
Apache has reported a vulnerability in the mod_cgid module when the threaded MPM is used. The problem is said to occur due to mishandling of CGI redirect paths. The condition may potentially cause CGI data to inadvertently be sent to the wrong client. Depending on the context of the data being redirected, this could potentially expose sensitive information or incorrectly grant unauthorized access.
Exploit / POC
Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
Solution:
Apache has released version 2.0.48 to address this issue. Users are advised to upgrade as soon as possible.
Conectiva have released an advisory (CLA-2003:775) and fixes to address this issue for Conectiva Linux. Affected users are advised to apply upgrades as soon as possible. Further information regarding obtaining and applying these upgrades is available in the referenced advisory.
Gentoo has released an advisory (200310-04) to address this issue. Affected users are advised to upgrade using the following procedure:
emerge sync
emerge '>=net-www/apache-2.0.48'
emerge clean
Mandrake has released an advisory (MDKSA-2003:103) to address this issue.
Please see the attached advisory for details on obtaining and applying fixes.
Further information regarding the application of this upgrade can be found in the referenced advisory.
Trustix has released security advisory 2003-0041 with fixes to address this issue.
HP has released security advisory HPSBUX0311-301 with fixes to address this issue. Affected users are advised to apply upgrades as soon as possible. Further information regarding obtaining and applying these upgrades is available in the referenced advisory.
Revised HP advisory has been released to address this issue.
Red Hat has released advisory RHSA-2003:320-01 to address this issue.
Apple has released advisory 2004-01-26 to address this issue.
Apache Apache 2.0
Apache Apache 2.0.28
Apache Apache 2.0.32
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Apache Apache 2.0.47
Solution:
Apache has released version 2.0.48 to address this issue. Users are advised to upgrade as soon as possible.
Conectiva have released an advisory (CLA-2003:775) and fixes to address this issue for Conectiva Linux. Affected users are advised to apply upgrades as soon as possible. Further information regarding obtaining and applying these upgrades is available in the referenced advisory.
Gentoo has released an advisory (200310-04) to address this issue. Affected users are advised to upgrade using the following procedure:
emerge sync
emerge '>=net-www/apache-2.0.48'
emerge clean
Mandrake has released an advisory (MDKSA-2003:103) to address this issue.
Please see the attached advisory for details on obtaining and applying fixes.
Further information regarding the application of this upgrade can be found in the referenced advisory.
Trustix has released security advisory 2003-0041 with fixes to address this issue.
HP has released security advisory HPSBUX0311-301 with fixes to address this issue. Affected users are advised to apply upgrades as soon as possible. Further information regarding obtaining and applying these upgrades is available in the referenced advisory.
Revised HP advisory has been released to address this issue.
Red Hat has released advisory RHSA-2003:320-01 to address this issue.
Apple has released advisory 2004-01-26 to address this issue.
Apache Apache 2.0
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.28
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.32
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.35
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.36
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.37
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.38
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.39
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.40
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz -
RedHat httpd-2.0.40-11.9.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-2.0.40-11.9.i386.rpm -
RedHat httpd-2.0.40-21.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.9.i386.rpm -
RedHat httpd-devel-2.0.40-11.9.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-devel-2.0.40-11.9.i386.r pm -
RedHat httpd-devel-2.0.40-21.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.9.i386.rpm -
RedHat httpd-manual-2.0.40-11.9.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-manual-2.0.40-11.9.i386. rpm -
RedHat httpd-manual-2.0.40-21.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.9.i386.rp m -
RedHat mod_ssl-2.0.40-11.9.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.9.i386.rpm -
RedHat mod_ssl-2.0.40-21.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.9.i386.rpm
Apache Apache 2.0.41
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.42
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.43
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.44
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz -
Conectiva apache-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_5cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_5cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 5cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_5cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_5cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_5cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_5cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_5cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_5cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_5cl .i386.rpm -
Mandrake apache2-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.6.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.6.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 2.0.45
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.46
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz
Apache Apache 2.0.47
-
Apache Software Foundation httpd-2.0.48.tar.gz
http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz -
Mandrake apache2-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-6.3.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
References
Apache Web Server mod_cgid Module CGI Data Redirection Vulnerability
References:
References:
- Apache httpd Release 2.0 Changes (Apache Software Foundation)