FreeBSD : mod_pubcookie -- Empty Authentication Security Advisory (1ca8228f-858d-11e0-a76c-000743057ca2)

High Nessus Plugin ID 54621


The remote FreeBSD host is missing a security-related update.


Nathan Dors, Pubcookie Project reports :

An Abuse of Functionality vulnerability in the Pubcookie authentication process was found. This vulnerability allows an attacker to appear as if he or she were authenticated using an empty userid when such a userid isn't expected. Unauthorized access to web content and applications may result where access is restricted to users who can authenticate successfully but where no additional authorization is performed after authentication.


Update the affected package.

See Also

Plugin Details

Severity: High

ID: 54621

File Name: freebsd_pkg_1ca8228f858d11e0a76c000743057ca2.nasl

Version: $Revision: 1.5 $

Type: local

Published: 2011/05/24

Modified: 2013/06/21

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:ap20-mod_pubcookie, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2011/05/23

Vulnerability Publication Date: 2006/10/04