FreeBSD : mod_pubcookie -- Empty Authentication Security Advisory (1ca8228f-858d-11e0-a76c-000743057ca2)

high Nessus Plugin ID 54621

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Nathan Dors, Pubcookie Project reports :

An Abuse of Functionality vulnerability in the Pubcookie authentication process was found. This vulnerability allows an attacker to appear as if he or she were authenticated using an empty userid when such a userid isn't expected. Unauthorized access to web content and applications may result where access is restricted to users who can authenticate successfully but where no additional authorization is performed after authentication.

Solution

Update the affected package.

See Also

http://www.pubcookie.org/news/20061106-empty-auth-secadv.html

http://www.nessus.org/u?d8adb788

Plugin Details

Severity: High

ID: 54621

File Name: freebsd_pkg_1ca8228f858d11e0a76c000743057ca2.nasl

Version: 1.9

Type: local

Published: 5/24/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:ap20-mod_pubcookie, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 5/23/2011

Vulnerability Publication Date: 10/4/2006