Vulnerability CVE-2004-1082


Published: 2004-02-03   Modified: 2008-09-05

Description:
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

Vendor: Openbsd
Product: Openbsd 
Version:
current
3.5
3.4
Vendor: HP
Product: Webproxy 
Version: a.02.10; a.02.00;
Product: Virtualvault 
Version:
4.7
4.6
4.5
Vendor: SUN
Product: Solaris 
Version: 9.0; 8.0;
Vendor: SCO
Product: Openserver 
Version: 5.0.7; 5.0.6;
Vendor: Avaya
Product: Communication manager 
Version:
2.0.1
2.0
1.3.1
1.1
Product: Modular messaging message storage server 
Version: 2.0; 1.1;
Product: Intuity audix lx 
Product: Mn100 
Product: Network routing 
Vendor: Apache
Product: Http server 
Version:
1.3.9
1.3.7
1.3.6
1.3.4
1.3.3
1.3.29
1.3.28
1.3.27
1.3.26
1.3.25
1.3.24
1.3.23
1.3.22
1.3.20
1.3.19
1.3.18
1.3.17
1.3.14
1.3.12
1.3.11
1.3.1
1.3
Vendor: IBM
Product: Http server 
Version: 1.3.19;
Vendor: Apple
Product: Apache mod digest apple 

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://xforce.iss.net/xforce/xfdb/18347
http://www.securitytracker.com/alerts/2004/Dec/1012414.html
http://www.securityfocus.com/bid/9571
http://www.ciac.org/ciac/bulletins/p-049.shtml
http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html

Related CVE
CVE-2017-2372
An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of se...
CVE-2017-2373
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cau...
CVE-2017-2374
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...
CVE-2017-2368
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
CVE-2017-2369
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cau...
CVE-2017-2370
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to ex...
CVE-2017-2371
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.
CVE-2017-2363
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attacker...

Copyright 2017, cxsecurity.com