OpenBSD httpd Access Rule Bypass Vulnerability
BID:9867
Info
OpenBSD httpd Access Rule Bypass Vulnerability
| Bugtraq ID: | 9867 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2004 12:00AM |
| Updated: | Mar 14 2004 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
OpenBSD OpenBSD 3.4 OpenBSD OpenBSD 3.3 |
| Not Vulnerable: | |
Discussion
OpenBSD httpd Access Rule Bypass Vulnerability
OpenBSD httpd access module is reported to allow unauthorized access. This is due to an error in the parsing of Allow/Deny rules with IP addresses without a netmask.
OpenBSD httpd access module is reported to allow unauthorized access. This is due to an error in the parsing of Allow/Deny rules with IP addresses without a netmask.
Exploit / POC
OpenBSD httpd Access Rule Bypass Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
OpenBSD httpd Access Rule Bypass Vulnerability
Solution:
Fixes are available:
OpenBSD OpenBSD 3.4
OpenBSD OpenBSD 3.3
Solution:
Fixes are available:
OpenBSD OpenBSD 3.4
-
OpenBSD 014_httpd2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/014_httpd2.patch
OpenBSD OpenBSD 3.3
-
OpenBSD 019_httpd2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.3/common/019_httpd2.patch
References
OpenBSD httpd Access Rule Bypass Vulnerability
References:
References:
- OpenBSD 3.3 release errata & patch list (OpenBSD)
- OpenBSD 3.4 release errata & patch list (OpenBSD)