Red Hat Bugzilla – Bug 137419
CAN-2003-0987 mod_digest nonce checking flaw
Last modified: 2008-01-28 11:30:52 EST
The mod_digest module does not properly verify the nonce of a client response by using a AuthNonce secret. This could allow a malicious user who is able to sniff network traffic to conduct a replay attack against a website using Digest protection. Note that mod_digest implements an older version of the MD5 Digest Authentication specification, which is known not to work with modern browsers. This issue does not affect mod_auth_digest. (CAN-2003-0987).
This issue is going to be RHSA-2004:600
An errata has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2004-600.html
*** Bug 126032 has been marked as a duplicate of this bug. ***