Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1312

Опубликовано: 21 мар. 2018
Источник: redhat
CVSS3: 4.2

Описание

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

Отчет

The "AuthType Digest" directive is not enabled in the default httpd configuration as shipped with Red Hat Enterprise Linux, and needs to be explicitly enabled. Therefore this flaw has no impact on the default versions of the httpd package as shipped with Red Hat Enterprise Linux. Also upstream discourages the use of mod_auth_digest because of its inherent security weaknesses and recommends the use of mod_ssl.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdWill not fix
Red Hat Enterprise Linux 6httpdWill not fix
Red Hat Enterprise Linux 8httpdNot affected
Red Hat JBoss Enterprise Web Server 2httpdWill not fix
Red Hat JBoss Web Server 3httpdNot affected
Red Hat Mobile Application Platform 4rhmap-httpd-dockerNot affected
JBoss Core Services on RHEL 6jbcs-httpd24FixedRHSA-2019:036718.02.2019
JBoss Core Services on RHEL 6jbcs-httpd24-apache-commons-daemon-jsvcFixedRHSA-2019:036718.02.2019
JBoss Core Services on RHEL 6jbcs-httpd24-aprFixedRHSA-2019:036718.02.2019
JBoss Core Services on RHEL 6jbcs-httpd24-apr-utilFixedRHSA-2019:036718.02.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=1560634httpd: Weak Digest auth nonce generation in mod_auth_digest

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

CVSS3: 9.8
nvd
почти 8 лет назад

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

CVSS3: 9.8
debian
почти 8 лет назад

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authen ...

CVSS3: 9.8
github
больше 3 лет назад

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.

oracle-oval
больше 6 лет назад

ELSA-2019-1898: httpd security update (LOW)

4.2 Medium

CVSS3