Apache mod_digest Client-Supplied Nonce Verification Vulnerability
BID:9571
Info
Apache mod_digest Client-Supplied Nonce Verification Vulnerability
| Bugtraq ID: | 9571 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0987 CVE-2004-1082 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | Discovery is credited to Dirk-Willem van Gulik. |
| Vulnerable: |
Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc SCO Open Server 5.0.7 SCO Open Server 5.0.6 Redhat Stronghold 4.0 OpenBSD OpenBSD 3.5 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD -current IBM HTTP Server 1.3.19 HP Webproxy A.02.10 HP Webproxy A.02.00 HP VirtualVault A.04.70 HP VirtualVault A.04.60 HP VirtualVault A.04.50 Avaya Network Routing Avaya Modular Messaging (MSS) 2.0 Avaya Modular Messaging (MSS) 1.1 Avaya MN100 Avaya Intuity LX Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 1.3.1 Avaya Communication Manager 1.1 Apple mod_digest_apple Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.14 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.1 Apache Apache 1.3 |
| Not Vulnerable: |
Posadis Posadis 1.3.31 Apache Apache 1.3.31 |
Discussion
Apache mod_digest Client-Supplied Nonce Verification Vulnerability
Patches have been released for the Apache mod_digest module to include digest replay protection. The module reportedly did not adequately verify client-supplied nonces against the server issued nonce. This could permit a remote attacker to replay the response of another website or section of the same website under some circumstances.
It should be noted that this issue does not exist in mod_auth_digest module.
Patches have been released for the Apache mod_digest module to include digest replay protection. The module reportedly did not adequately verify client-supplied nonces against the server issued nonce. This could permit a remote attacker to replay the response of another website or section of the same website under some circumstances.
It should be noted that this issue does not exist in mod_auth_digest module.
Exploit / POC
Apache mod_digest Client-Supplied Nonce Verification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache mod_digest Client-Supplied Nonce Verification Vulnerability
Solution:
The following referenced patch will be included in the upcoming release of Apache 1.3.30:
http://www.mail-archive.com/[email protected]/msg19007.html
This fix is also reportedly available through CVS.
Avaya has released an advisory (ASA-2005-010_RHSA-2004-600) that acknowledges this vulnerability for Avaya products. Please see the referenced Avaya advisory for further details.
SCO has released an advisory (SCOSA-2004.14) to address this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information regarding obtaining fixes for affected operating systems.
Sun has released an alert (Alert ID: 57628) that includes workarounds and preliminary T-Patches to address this and other issues in Apache. Customers are advised to read the referenced advisory for further information pertaining to obtaining and applying appropriate workarounds and T-Patches.
OpenPKG has released an advisory OpenPKG-SA-2004.021 to address this and other issues in Apache. Please see the referenced advisory for more information.
Slackware has released an advisory SSA:2004-133-01 to address this and other issues in Apache. Please see the referenced advisory for more information.
Trustix has released an advisory TSLSA-2004-0027 to address this and other issues in Apache. Please see the referenced advisory for more information.
Mandrake has issued advisory MDKSA-2004:046 and fixes. See advisory in the reference section for more information.
Mandrake has issued a revised advisory and fixes. See advisory MDKSA-2004:046-1 in the reference section for more information.
Turbolinux has issued advisory TLSA-2004-17 and fixes. See advisory in the reference section for more information.
OpenBSD has released patches for OpenBSD 3.4 and 3.5. Please see the patch files for instructions on applying and rebuilding the affected binaries. New snapshots and OpenBSD-current as of 12 June 2004 contain the fixes as well.
Apache Server version 1.3.31 has been released to address this and other issues.
HP has released an advisory (HPSBUX01069) to address this and other issues. Please see the referenced advisory for more information.
Sun has released an alert (Alert ID: 57628) containing preliminary T-patches to address this and other issues in Apache. Please see the advisory in web references for more information.
Sun has released an update to Sun Alert ID: 57628. Patches for Solaris 9.0 have been made available. Patches for Solaris 8.0 are still pending.
Sun has released an update to Sun Alert ID: 57628. T-Patches (T116973-01, T116974-01) are available through normal support channels for Solaris 8 SPARC platform and Solaris 8 x86 platform. Please see the referenced Sun alert for more information.
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. This security update resolves this issue by installing Apache version 1.3.33, which has been fixed against this issue. Furthermore Apple has announced that this issue also affects its mod_digest_apple. The affected module is patched with the associated security update as well. Please see the referenced advisory for more information.
Red Hat has released advisory RHSA-2004:600-12 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Red Hat has released advisory RHSA-2005:816-10 to address this issue for Red Hat Stronghold for Enterprise Linux. Please see the referenced advisory for further information on obtaining fixes.
OpenBSD OpenBSD 3.5
Apple mod_digest_apple
OpenBSD OpenBSD 3.4
Sun Solaris 9
Sun Solaris 9_x86
Apache Apache 1.3
Apache Apache 1.3.1
Apache Apache 1.3.11
Apache Apache 1.3.12
Apache Apache 1.3.14
Apache Apache 1.3.17
Apache Apache 1.3.18
Apache Apache 1.3.19
Apache Apache 1.3.20
Apache Apache 1.3.22
Apache Apache 1.3.23
Apache Apache 1.3.24
Apache Apache 1.3.25
Apache Apache 1.3.26
Apache Apache 1.3.27
Apache Apache 1.3.28
Apache Apache 1.3.29
Apache Apache 1.3.3
Apache Apache 1.3.4
Apache Apache 1.3.6
Apache Apache 1.3.7 -dev
Apache Apache 1.3.9
Solution:
The following referenced patch will be included in the upcoming release of Apache 1.3.30:
http://www.mail-archive.com/[email protected]/msg19007.html
This fix is also reportedly available through CVS.
Avaya has released an advisory (ASA-2005-010_RHSA-2004-600) that acknowledges this vulnerability for Avaya products. Please see the referenced Avaya advisory for further details.
SCO has released an advisory (SCOSA-2004.14) to address this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information regarding obtaining fixes for affected operating systems.
Sun has released an alert (Alert ID: 57628) that includes workarounds and preliminary T-Patches to address this and other issues in Apache. Customers are advised to read the referenced advisory for further information pertaining to obtaining and applying appropriate workarounds and T-Patches.
OpenPKG has released an advisory OpenPKG-SA-2004.021 to address this and other issues in Apache. Please see the referenced advisory for more information.
Slackware has released an advisory SSA:2004-133-01 to address this and other issues in Apache. Please see the referenced advisory for more information.
Trustix has released an advisory TSLSA-2004-0027 to address this and other issues in Apache. Please see the referenced advisory for more information.
Mandrake has issued advisory MDKSA-2004:046 and fixes. See advisory in the reference section for more information.
Mandrake has issued a revised advisory and fixes. See advisory MDKSA-2004:046-1 in the reference section for more information.
Turbolinux has issued advisory TLSA-2004-17 and fixes. See advisory in the reference section for more information.
OpenBSD has released patches for OpenBSD 3.4 and 3.5. Please see the patch files for instructions on applying and rebuilding the affected binaries. New snapshots and OpenBSD-current as of 12 June 2004 contain the fixes as well.
Apache Server version 1.3.31 has been released to address this and other issues.
HP has released an advisory (HPSBUX01069) to address this and other issues. Please see the referenced advisory for more information.
Sun has released an alert (Alert ID: 57628) containing preliminary T-patches to address this and other issues in Apache. Please see the advisory in web references for more information.
Sun has released an update to Sun Alert ID: 57628. Patches for Solaris 9.0 have been made available. Patches for Solaris 8.0 are still pending.
Sun has released an update to Sun Alert ID: 57628. T-Patches (T116973-01, T116974-01) are available through normal support channels for Solaris 8 SPARC platform and Solaris 8 x86 platform. Please see the referenced Sun alert for more information.
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. This security update resolves this issue by installing Apache version 1.3.33, which has been fixed against this issue. Furthermore Apple has announced that this issue also affects its mod_digest_apple. The affected module is patched with the associated security update as well. Please see the referenced advisory for more information.
Red Hat has released advisory RHSA-2004:600-12 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Red Hat has released advisory RHSA-2005:816-10 to address this issue for Red Hat Stronghold for Enterprise Linux. Please see the referenced advisory for further information on obtaining fixes.
OpenBSD OpenBSD 3.5
-
OpenBSD 013_httpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/013_httpd.patch
Apple mod_digest_apple
-
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg
OpenBSD OpenBSD 3.4
-
OpenBSD 025_httpd3.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/025_httpd3.patch
Sun Solaris 9
-
Sun T-patch T113146-05.tar.Z
http://sunsolve.sun.com/pub-cgi/show.pl?target=security/tpatches -
Sun 113146-05
http://sunsolve.sun.com/search/pdownload.pl?target=113146-05&method=hs
Sun Solaris 9_x86
-
Sun T-patch T114145-04.tar.Z
http://sunsolve.sun.com/pub-cgi/show.pl?target=security/tpatches -
Sun 114145-04
http://sunsolve.sun.com/search/pdownload.pl?target=114145-04&method=hs
Apache Apache 1.3
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.1
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.11
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.12
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.14
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.17
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.18
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.19
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.20
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.22
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.23
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.24
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.25
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.26
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Mandrake apache-mod_perl-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.26_1.3.4-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.26_1.3.4-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 1.3.27
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Mandrake apache-mod_perl-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.27_1.3.4-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.27_1.3.4-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/mod_ssl-2.8.14-23.i586.rpm
Apache Apache 1.3.28
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Mandrake apache-mod_perl-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.28_1.3.4-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.28_1.3.4-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 1.3.29
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg -
Mandrake apache-mod_perl-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.29_1.3.6-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.29_1.3.6-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Slackware apache-1.3.29-i386-2.tgz
Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/a pache-1.3.29-i386-2.tgz -
Slackware apache-1.3.29-i386-2.tgz for Slackware 9.0
Updated package for Slackware 9.0
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/a pache-1.3.29-i386-2.tgz -
Slackware apache-1.3.29-i486-2.tgz
Updated package for Slackware 9.1
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/a pache-1.3.29-i486-2.tgz
Apache Apache 1.3.3
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.4
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.6
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.7 -dev
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Apache 1.3.9
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
References
Apache mod_digest Client-Supplied Nonce Verification Vulnerability
References:
References:
- [patch] - digest nonce including MM bump, doc and changes. (Dirk-Willem van Gulik)
- Apache Homepage (Apache Software Foundation)
- ASA-2005-010_RHSA-2004-600 (Avaya)
- OpenBSD Errata Page (OpenBSD)
- RHSA-2004:600-12 - Updated apache and mod_ssl packages fix security vulnerabilit (RedHat)
- RHSA-2005:816-10 - apache, mod_ssl, php update for Stronghold (RedHat)
- Sun Alert ID: 57628 (Sun)