SA61 : Director multiple Apache vulnerabilities
1232
03 March 2020
13 September 2011
CLOSED
HIGH
CVSS v2: 8.3
SUMMARY
Director uses a version of Apache httpd that has several publicly documented vulnerabilities. The most severe vulnerability allows an attacker to gain complete control over a Director installation.
AFFECTED PRODUCTS
All versions of Director prior to 5.5.2.3 are vulnerable.
Patches
- Director 5.5 - an interim fix is available in 5.5.2.3.
- Director 5.4 and earlier - please upgrade to a later release.
ISSUES
Director 5.4 and 5.5.1.1 use Apache httpd version 2.0.63. The version of Apache has several publicly documented vulnerabilities.
The most severe vulnerability allows an attacker to gain complete control over a Director installation. The attacker can view and modify configuration data as well as data sent to and from Director. An attacker can also render Director completely unresponsive for administrative control as well as data transmission.
When Director is deployed behind a firewall, as is recommended, an attacker must gain access from the internal network in order to mount an attack. The CVSS base scores included in this advisory are based on this deployment scenario.
If Director is deployed outside of the firewall, the CVSS base score for all CVEs listed would be higher. The CVSS base score for this security advisory would be a 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C).
Director 5.5.2.3 contains an upgrade to Apache httpd version 2.0.64 fixing the CVEs documented in this security advisory.
MITIGATION
Blue Coat recommends that Director be deployed behind a firewall. Additional constraints on what IP addresses can be used to connect to Director will greatly limit the ability to attack a Director installation.
REFERENCES
CVE-2010-1623 - https://nvd.nist.gov/vuln/detail/CVE-2010-1623
CVE-2010-1452 - https://nvd.nist.gov/vuln/detail/CVE-2010-1452
CVE-2010-0434 - https://nvd.nist.gov/vuln/detail/CVE-2010-0434
CVE-2010-0425 - https://nvd.nist.gov/vuln/detail/CVE-2010-0425
CVE-2009-3720 - https://nvd.nist.gov/vuln/detail/CVE-2009-3720
CVE-2009-3560 - https://nvd.nist.gov/vuln/detail/CVE-2009-3560
CVE-2009-3555 - https://nvd.nist.gov/vuln/detail/CVE-2009-3555
CVE-2009-3095 - https://nvd.nist.gov/vuln/detail/CVE-2009-3095
CVE-2009-3094 - https://nvd.nist.gov/vuln/detail/CVE-2009-3094
CVE-2009-2412 - https://nvd.nist.gov/vuln/detail/CVE-2009-2412
CVE-2009-1891 - https://nvd.nist.gov/vuln/detail/CVE-2009-1891
CVE-2008-2939 - https://nvd.nist.gov/vuln/detail/CVE-2008-2939
CVE-2008-2364 - https://nvd.nist.gov/vuln/detail/CVE-2008-2364
REVISION
2015-01-20 Marked as final
2012-01-17 Adjusted formatting problems
2011-09-13 Initial public release