oss-sec mailing list archives
Apache symlink issue: can documented behavior be a security problem and hence get a CVE?
From: halfdog <me () halfdog net>
Date: Tue, 12 Jul 2011 11:20:54 +0000
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello List, Is it possible to assign a CVE for documented behavior? Communication with apache security showed, that following symlinks to arbitrary locations is a documented feature, even when "-FollowSymLink" option is in place. This allows any user with, that can modify some content served by apache to access any content accessible by the apache process, also content not visible to the user (e.g. outside the ftp-upload directory or forbidden like /proc/http-pid/maps). Due to the small window of opportunity, this might be relevant mostly when user can already execute code on the machine, so it is not a big issue. /proc/<pid>/mem is protected, when apache is running with setuid, so key material cannot be extracted using range headers. PUT was not tested so far. See also http://www.halfdog.net/Security/2011/ApacheNoFollowSymlinkTimerace/ - -- http://www.halfdog.net/ PGP: 156A AE98 B91F 0114 FE88 2BD8 C459 9386 feed a bee -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFOHC4exFmThv7tq+4RAooyAJ9Vh7F49em+AVT1HosEquCPS+olqQCfdVCO PDcCdoHHWTCHe53U+XTzefY= =fVzn -----END PGP SIGNATURE-----
Current thread:
- Apache symlink issue: can documented behavior be a security problem and hence get a CVE? halfdog (Jul 12)
- Re: Apache symlink issue: can documented behavior be a security problem and hence get a CVE? Mike O'Connor (Jul 12)
- Re: Apache symlink issue: can documented behavior be a security problem and hence get a CVE? Josh Bressers (Jul 12)
- Re: Apache symlink issue: can documented behavior be a security problem and hence get a CVE? Steven M. Christey (Jul 13)