OSVDB ID: 8242

Title: Pavuk Digest Authentication Overflow

Info

Disclosure

Jul 27, 2004

Discovery

Jul 09, 2004

Dates

Exploit

Aug 07, 2004

Solution

Unknown

Description

A remote overflow exists in Pavuk. The program fails to properly check nonce and realm fields which accompany a digest authentication challenge upon the receipt of a 401 (unauthorized) http error resulting in an overflow in sprintf() in the digest authentication handler. With a specially crafted response, an attacker can cause execution of arbitrary code resulting in a loss of confidentiality, integrity, and/or availability.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Disable http digest authentication or upgrade to version 0.928r3 or higher, as it has been reported to fix this vulnerability.

Products

Stefan Ondrejicka

Pavuk

0.928r1
0.928r2
0.9pl28i

References

Credit

  • Matthew Murphy - mattmurphykc.rr.com -


Direct URL: http://osvdb.org/8242