Vulnerability Note VU#849993
Some implementations of mod_dav contain a format string vulnerability in "ap_log_rerror()" function
Overview
A vulnerability in some implementations of mod_dav may permit a remote attacker to gain unauthorized access to a web server running mod_dav.
Description
mod_dav is a module designed to provide DAV capabilities for a web server. A format string vulnerability in some implementations may permit a remote attacker to gain unauthorized access to a web server running mod_dav. Here is a brief primer for those unfamiliar with format string vulnerabilities: |
Impact
A remote attacker may be able to gain privileged access to a web server running mod_dav. |
Solution
Apply a vendor patch. |
You may wish to disable mod_dav until a patch can be applied. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Oracle Corporation | Affected | - | 14 Feb 2003 |
| Apple Computer Inc. | Not Affected | 25 Sep 2002 | 24 Jul 2003 |
| Cray Inc. | Not Affected | 25 Sep 2002 | 25 Sep 2002 |
| IBM | Not Affected | 25 Sep 2002 | 27 Sep 2002 |
| Microsoft Corporation | Not Affected | - | 06 Nov 2002 |
| OpenBSD | Not Affected | 25 Sep 2002 | 26 Sep 2002 |
| Openwall GNU/*/Linux | Not Affected | 25 Sep 2002 | 06 Nov 2002 |
| Red Hat Inc. | Not Affected | 25 Sep 2002 | 18 Feb 2003 |
| Xerox Corporation | Not Affected | 25 Sep 2002 | 30 May 2003 |
| 3Com | Unknown | 25 Sep 2002 | 25 Sep 2002 |
| Alcatel | Unknown | 25 Sep 2002 | 25 Sep 2002 |
| AT&T | Unknown | 25 Sep 2002 | 25 Sep 2002 |
| BSDI | Unknown | 25 Sep 2002 | 25 Sep 2002 |
| Cisco Systems Inc. | Unknown | 25 Sep 2002 | 25 Sep 2002 |
| Computer Associates | Unknown | 25 Sep 2002 | 25 Sep 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.nextgenss.com/advisories/ora-appservfmtst.txt
- http://otn.oracle.com/deploy/security/pdf/2003alert52.pdf
- http://www.webdav.org/mod_dav/
Credit
This vulnerability was discovered by David Litchfield of Next Generation Security Software Ltd. The CERT/CC thanks both Next Generation Security Software Ltd and Oracle for providing information upon which this document is based.
This document was written by Ian A Finlay and Shawn V. Hernan.
Other Information
- CVE IDs: CAN-2002-0842
- Date Public: 11 Feb 2003
- Date First Published: 18 Feb 2003
- Date Last Updated: 24 Jul 2003
- Severity Metric: 28.12
- Document Revision: 36
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.