Apache mod_digest Client-Supplied Nonce Verification Vulnerability

Solution:
The following referenced patch will be included in the upcoming release of Apache 1.3.30:

http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html

This fix is also reportedly available through CVS.

Avaya has released an advisory (ASA-2005-010_RHSA-2004-600) that acknowledges this vulnerability for Avaya products. Please see the referenced Avaya advisory for further details.

SCO has released an advisory (SCOSA-2004.14) to address this issue for OpenServer 5.0.6 and 5.0.7. Please see the referenced advisory for further information regarding obtaining fixes for affected operating systems.

Sun has released an alert (Alert ID: 57628) that includes workarounds and preliminary T-Patches to address this and other issues in Apache. Customers are advised to read the referenced advisory for further information pertaining to obtaining and applying appropriate workarounds and T-Patches.

OpenPKG has released an advisory OpenPKG-SA-2004.021 to address this and other issues in Apache. Please see the referenced advisory for more information.

Slackware has released an advisory SSA:2004-133-01 to address this and other issues in Apache. Please see the referenced advisory for more information.

Trustix has released an advisory TSLSA-2004-0027 to address this and other issues in Apache. Please see the referenced advisory for more information.

Mandrake has issued advisory MDKSA-2004:046 and fixes. See advisory in the reference section for more information.

Mandrake has issued a revised advisory and fixes. See advisory MDKSA-2004:046-1 in the reference section for more information.

Turbolinux has issued advisory TLSA-2004-17 and fixes. See advisory in the reference section for more information.

OpenBSD has released patches for OpenBSD 3.4 and 3.5. Please see the patch files for instructions on applying and rebuilding the affected binaries. New snapshots and OpenBSD-current as of 12 June 2004 contain the fixes as well.

Apache Server version 1.3.31 has been released to address this and other issues.

HP has released an advisory (HPSBUX01069) to address this and other issues. Please see the referenced advisory for more information.

Sun has released an alert (Alert ID: 57628) containing preliminary T-patches to address this and other issues in Apache. Please see the advisory in web references for more information.

Sun has released an update to Sun Alert ID: 57628. Patches for Solaris 9.0 have been made available. Patches for Solaris 8.0 are still pending.

Sun has released an update to Sun Alert ID: 57628. T-Patches (T116973-01, T116974-01) are available through normal support channels for Solaris 8 SPARC platform and Solaris 8 x86 platform. Please see the referenced Sun alert for more information.

Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. This security update resolves this issue by installing Apache version 1.3.33, which has been fixed against this issue. Furthermore Apple has announced that this issue also affects its mod_digest_apple. The affected module is patched with the associated security update as well. Please see the referenced advisory for more information.

Red Hat has released advisory RHSA-2004:600-12 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.

Red Hat has released advisory RHSA-2005:816-10 to address this issue for Red Hat Stronghold for Enterprise Linux. Please see the referenced advisory for further information on obtaining fixes.


OpenBSD OpenBSD 3.5

Apple mod_digest_apple

OpenBSD OpenBSD 3.4

Sun Solaris 9

Sun Solaris 9_x86

Apache Apache 1.3

Apache Apache 1.3.1

Apache Apache 1.3.11

Apache Apache 1.3.12

Apache Apache 1.3.14

Apache Apache 1.3.17

Apache Apache 1.3.18

Apache Apache 1.3.19

Apache Apache 1.3.20

Apache Apache 1.3.22

Apache Apache 1.3.23

Apache Apache 1.3.24

Apache Apache 1.3.25

Apache Apache 1.3.26

Apache Apache 1.3.27

Apache Apache 1.3.28

Apache Apache 1.3.29

Apache Apache 1.3.3

Apache Apache 1.3.4

Apache Apache 1.3.6

Apache Apache 1.3.7 -dev

Apache Apache 1.3.9


 

Privacy Statement
Copyright 2010, SecurityFocus