Bug 137465 - mod_disk_cache information disclosure
Summary: mod_disk_cache information disclosure
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: httpd
Version: 3.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Joe Orton
QA Contact:
URL:
Whiteboard:
: 157474 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-10-28 17:30 UTC by Josh Bressers
Modified: 2007-11-30 22:07 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-11-25 15:49:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2004-10-28 17:30:33 UTC
mod_disk_cache stores all client authentication credentials for cached
objects on disk. This means proxy authentication credentials as well as
in certain RFC2616 defined cases standard authentication credentials.

In case of Basic Authentication *plaintext passwords* are stored on disk.

See
http://www.securityfocus.com/archive/1/358099/2004-03-14/2004-03-20/0
for more information and patch.

Comment 1 Joe Orton 2004-11-09 14:45:44 UTC
Should be fixed in 2.0.46-44.ent update.

Comment 2 Mark J. Cox 2004-11-25 15:49:57 UTC
http://rhn.redhat.com/errata/RHSA-2004-562.html

Comment 3 Mark J. Cox 2005-05-12 09:40:12 UTC
*** Bug 157474 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.