Mod-Auth-Shadow Apache Module Expired User Credential Weakness
BID:9404
Info
Mod-Auth-Shadow Apache Module Expired User Credential Weakness
| Bugtraq ID: | 9404 |
| Class: | Design Error |
| CVE: |
CVE-2004-0041 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2004 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Discovery credited to David B Harris. |
| Vulnerable: |
mod_auth_shadow mod_auth_shadow 1.3 mod_auth_shadow mod_auth_shadow 1.2 mod_auth_shadow mod_auth_shadow 1.1 mod_auth_shadow mod_auth_shadow 1.0 |
| Not Vulnerable: |
mod_auth_shadow mod_auth_shadow 1.4 |
Discussion
Mod-Auth-Shadow Apache Module Expired User Credential Weakness
A problem has been identified in mod-auth-shadow that may permit a user to gain access to a web site after the expiration of their credentials. This weakness may result in users gaining access to the web site outside of the period of validity for their credentials.
A problem has been identified in mod-auth-shadow that may permit a user to gain access to a web site after the expiration of their credentials. This weakness may result in users gaining access to the web site outside of the period of validity for their credentials.
Exploit / POC
Mod-Auth-Shadow Apache Module Expired User Credential Weakness
No exploit is required.
No exploit is required.
Solution / Fix
Mod-Auth-Shadow Apache Module Expired User Credential Weakness
Solution:
Debian has released advisory DSA 421-1 to address this issue.
mod_auth_shadow mod_auth_shadow 1.3
Solution:
Debian has released advisory DSA 421-1 to address this issue.
mod_auth_shadow mod_auth_shadow 1.3
-
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_alpha.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_arm.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_hppa.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_i386.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_ia64.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_m68k.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_mips.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_mipsel.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_powerpc.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_s390.deb -
Debian libapache-mod-auth-shadow_1.3-3.1woody.1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/m/mod-auth-shadow/libapac he-mod-auth-shadow_1.3-3.1woody.1_sparc.deb
References
Mod-Auth-Shadow Apache Module Expired User Credential Weakness
References:
References:
- Project Homepage (mod_auth_shadow)