Bug 851387 (CVE-2011-4973) - VUL-0: CVE-2011-4973: apache2-mod_nss: FakeBasicAuth authentication bypass
Summary: VUL-0: CVE-2011-4973: apache2-mod_nss: FakeBasicAuth authentication bypass
Status: RESOLVED FIXED
Alias: CVE-2011-4973
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Roman Drahtmueller
QA Contact: Security Team bot
URL:
Whiteboard: .
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-20 17:17 UTC by Marcus Meissner
Modified: 2013-11-25 10:44 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-11-20 17:17:21 UTC
CVE-2011-4973 , via oss-sec


A FakeBasicAuth authentication bypass issue was reported for mod_nss
some time ago:

https://www.redhat.com/archives/mod_nss-list/2011-May/msg00001.html

The issue was fixed in upstream git:

https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=a6c3370491ae1d3bc552e8de9353c82f73e510e3

but there was no new release of mod_nss since to include the fix.

The issue now got CVE-2011-4973 assigned.

Note that the fix changes the user name that needs to be specified in
htpasswd when using FakeBasicAuth.

-- 
Tomas Hoger / Red Hat Security Response Team

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1017197
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4973
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4973
Comment 1 Swamp Workflow Management 2013-11-20 23:00:21 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2013-11-25 10:43:47 UTC
already fixed in tested update.