Bug 538322 (CVE-2009-3095) - VUL-0: CVE-2009-3095: apache2: mod_proxy_ftp bypass intended access restrictions and DoS
Summary: VUL-0: CVE-2009-3095: apache2: mod_proxy_ftp bypass intended access restricti...
Status: RESOLVED FIXED
Alias: CVE-2009-3095
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Deadline: 2009-09-25
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2009-3095: CVSS v2 Base Score: 7....
Keywords:
Depends on:
Blocks:
 
Reported: 2009-09-11 08:24 UTC by Thomas Biege
Modified: 2015-09-25 13:16 UTC (History)
4 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Biege 2009-09-11 08:24:01 UTC
Hi.
There is a security bug in 'apache2'.

This bug is public.

There is no coordinated release date (CRD) set.

CVE number: CVE-2009-3095
CVE description: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095


Original posting:


 send arbitrary

CVE-ID: CVE-2009-3095
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095


The mod_proxy_ftp module in the Apache HTTP Server allows remote
attackers to bypass intended access restrictions and send arbitrary
commands to an FTP server via vectors related to the embedding of
these commands in the Authorization HTTP header, as demonstrated by a
certain module in VulnDisco Pack Professional 8.11.  NOTE: as of
20090903, this disclosure has no actionable information. However,
because the VulnDisco Pack author is a reliable researcher, the issue
is being assigned a CVE identifier for tracking purposes.


Current Votes:
None (candidate not yet proposed)
Comment 1 Thomas Biege 2009-09-11 09:00:06 UTC
CVE-2009-3094
	
Description
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
Comment 2 Thomas Biege 2009-09-11 09:01:21 UTC
MaintenanceTracker-25282
Comment 3 Marcus Meissner 2009-10-13 09:51:00 UTC
no information received on how to fix yet, cve entry is without any refs
Comment 4 Thomas Biege 2009-10-14 03:01:09 UTC
CVE-2009-3095: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Comment 7 Marcus Meissner 2009-10-16 14:44:20 UTC
submitted fixed packages and patchinfos for sles9,sle10sp2,sp3,10.3,11.0,sle11,stable
Comment 8 Swamp Workflow Management 2009-10-23 15:50:40 UTC
Update released for: apache2, apache2-debuginfo, apache2-debugsource, apache2-devel, apache2-doc, apache2-event, apache2-example-pages, apache2-prefork, apache2-utils, apache2-worker
Products:
openSUSE 10.3 (i386, ppc, x86_64)
openSUSE 11.0 (debug, i386, ppc, x86_64)
openSUSE 11.1 (debug, i586, ppc, x86_64)
Comment 9 Marcus Meissner 2009-10-23 15:51:45 UTC
released updates.
Comment 10 Swamp Workflow Management 2009-10-23 22:08:33 UTC
Update released for: apache2, apache2-devel, apache2-doc, apache2-example-pages, apache2-leader, apache2-metuxmpm, apache2-perchild, apache2-prefork, apache2-worker, libapr0
Products:
Novell-Linux-Desktop 9 (i386, x86_64)
Novell-Linux-POS 9 (i386)
Open-Enterprise-Server 9 (i386)
SUSE-CORE 9 (i386, ia64, ppc, s390, s390x, x86_64)
Comment 11 Swamp Workflow Management 2009-10-23 22:09:06 UTC
Update released for: apache2, apache2-debuginfo, apache2-debugsource, apache2-devel, apache2-doc, apache2-event, apache2-example-pages, apache2-prefork, apache2-utils, apache2-worker
Products:
SLE-DEBUGINFO 11 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11 (i386, ia64, ppc64, s390x, x86_64)
Comment 12 Swamp Workflow Management 2009-10-23 22:09:25 UTC
Update released for: apache2, apache2-devel, apache2-doc, apache2-event, apache2-example-pages, apache2-prefork, apache2-worker
Products:
SLE-DEBUGINFO 10-SP2 (i386, ia64, ppc, s390x, x86_64)
SLE-SDK 10-SP2 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP2 (i386, ia64, ppc, s390x, x86_64)
Comment 13 Swamp Workflow Management 2009-10-23 22:09:33 UTC
Update released for: apache2, apache2-debuginfo, apache2-devel, apache2-doc, apache2-event, apache2-example-pages, apache2-prefork, apache2-worker
Products:
SLE-DEBUGINFO 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SDK 10-SP3 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)