OSVDB ID: 6475

Title: FastCGI mod_fastcgi subprocess_env Password Disclosure

Info

Disclosure

Apr 25, 1999

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

FastCGI mod_fastcgi contains a flaw that may allow an attacker to discover authentication credentials. The issue is due to the subprocess_env table not properly sanitizing variables between authentication requests. This allows for the process to pass variables including REMOTE_PASSWD to other processing phases and may allow for disclosure to unauthorized individuals.

Classification

Location: Unknown Location
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 2.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

FastCGI

mod_fastcgi

2.2.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218