This application requires Javascript for optimal performance.

HTTP.Server.Authorization.Basic.Handling.Format.String

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Format String vulnerability in Apache auth_ldap.

The vulnerability is caused by an input validation error in the "auth_ldap_log_reason" function. It allows remote attackers to execute arbitrary code via a maliciously crafted username.

Affected Products

Apache auth_ldap 1.6.0 and earlier versions

Recommended Actions

Upgrade to auth_ldap (1.6.1 or later), available from the web site below:
http://www.rudedog.org/auth_ldap/Changes.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0150

Reference/s

http://www.securityfocus.com/bid/16177 (BugTraq)

Reference: VID-30433