CVE Vulnerabilities

CVE-2005-2963

Published: Oct 13, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

Affected Software

Name Vendor Start Version End Version
Mod_auth_shadow Mod_auth_shadow 1.0 (including) 1.0 (including)
Mod_auth_shadow Mod_auth_shadow 1.1 (including) 1.1 (including)
Mod_auth_shadow Mod_auth_shadow 1.2 (including) 1.2 (including)
Mod_auth_shadow Mod_auth_shadow 1.3 (including) 1.3 (including)
Mod_auth_shadow Mod_auth_shadow 1.4 (including) 1.4 (including)
Mod_auth_shadow Mod_auth_shadow 1.5 (including) 1.5 (including)
Mod_auth_shadow Mod_auth_shadow 2.0 (including) 2.0 (including)
Mod-auth-shadow Ubuntu dapper *
Mod-auth-shadow Ubuntu edgy *
Mod-auth-shadow Ubuntu feisty *

References