Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2003-0987
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0987

Description:
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/15041

TRUSTIX
  http://www.trustix.org/errata/2004/0027

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-101841-1
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1

ST
  1008920

SLACKWARE
  http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643

REDHAT
  http://www.redhat.com/support/errata/RHSA-2004-600.html
  http://www.redhat.com/support/errata/RHSA-2005-816.html

OVAL
  http://oval.mitre.org/oval/definitions/data/oval4416.html
  http://oval.mitre.org/oval/definitions/data/oval100108.html

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:046

GENTOO
  http://security.gentoo.org/glsa/glsa-200405-22.xml

CONFIRM
  http://www.mail-archive.com/dev@httpd.apache.org/msg19007.html
  http://www.mail-archive.com/dev@httpd.apache.org/msg19014.html

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=108437852004207&w=2

BID
  9571


Return to the previous page.