LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

mod_auth_any: remote exploit

Package(s):mod_auth_any CVE #(s):CAN-2003-0084
Created:May 2, 2003 Updated:May 7, 2003
Description: mod_auth_any is a web server module that allows the Apache httpd server to call arbitrary external programs to verify user passwords.

Vulnerabilities have been found in the way mod_auth_any escapes shell arguments when calling external programs. These vulnerabilities allow remote attackers to run arbitrary commands as the user under which the Web server is running.

Alerts:
Red Hat RHSA-2003:113-01 2002-03-05

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds