imPC@ndo IT

Tracker / CVE-2004-1082

CVE-2004-1082

High 7.5

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

Affected products and versions

apache http_server
apple apache_mod_digest_apple
avaya communication_manager
avaya intuity_audix_lx
avaya mn100
avaya modular_messaging_message_storage_server
avaya network_routing
hp virtualvault
hp webproxy
ibm http_server
openbsd openbsd
sco openserver
sun solaris
sun sunos

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References