Nessus Plugin #12239

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Apache Error Log Escape Sequence Injection

Family:
General
Category:
infos
Copyright:
This script is Copyright (C) 2004 George A. Theall
Summary:
Checks for Apache Error Log Escape Sequence Injection Vulnerability
Version:
$Revision: 1.7 $
Cve_id:
CAN-2003-0020
Bugtraq_id:
9930
Xrefs:
APPLE-SA:APPLE-SA-2004-05-03, CLSA:CLSA-2004:839, HPSB:HPSBUX01022, RHSA:RHSA-2003:139-07, RHSA:RHSA-2003:243-07, MDKSA:MDKSA-2003:050, OpenPKG-SA:OpenPKG-SA-2004.021-apache, SSA:SSA:2004-133-01, SuSE-SA:SuSE-SA:2004:009, TLSA:TLSA-2004-11, TSLSA:TSLSA-2004-0017
Description:

The target is running an Apache web server which allows for the
injection of arbitrary escape sequences into its error logs. An
attacker might use this vulnerability in an attempt to exploit similar
vulnerabilities in terminal emulators.

***** Nessus has determined the vulnerability exists only by looking at
***** the Server header returned by the web server running on the target.

Solution : Upgrade to Apache version 1.3.31 or 2.0.49 or newer.
Risk factor : Low
Generiert am 27.04.2005 um 18:49:54 Uhr.