MEDIUM
mod_auth_shadow: bad wait(2) call causes randomized authorization behaviour
Published Apr 20, 2010
6.8
MEDIUMCVSS 2.0
EPSS 3.77%
Description
Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.
Affected products
No data.
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/39823 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:081 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/39538 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/0908 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/1148 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=578168 x_refsource_CONFIRMPatchIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1151
- https://www.cve.org/CVERecord?id=CVE-2010-1151
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html | vendor-advisoryx_refsource_FEDORA | |
| http://secunia.com/advisories/39823 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:081 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.securityfocus.com/bid/39538 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2010/0908 | vdb-entryx_refsource_VUPEN | |
| http://www.vupen.com/english/advisories/2010/1148 | vdb-entryx_refsource_VUPEN | |
| https://access.redhat.com/security/cve/CVE-2010-1151 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=578168 | x_refsource_CONFIRMPatchIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-1151 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-1151 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 20, 2010
Updated Aug 7, 2024
Reserved Mar 29, 2010
Link CVE-2010-1151
CISA Vulnrichment
Updated n/a