Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 477930 (CVE-2013-2249) - <www-servers/apache-2.4.5: Session fixation flaw in mod_session_dbd (CVE-2013-2249)
Summary: <www-servers/apache-2.4.5: Session fixation flaw in mod_session_dbd (CVE-2013...
Status: RESOLVED FIXED
Alias: CVE-2013-2249
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-23 16:49 UTC by Agostino Sarubbo
Modified: 2014-08-26 14:36 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-07-23 16:49:31 UTC
From ${URL} :

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2249 to
the following vulnerability:

Name: CVE-2013-2249
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2249
Assigned: 20130219
Reference: 
http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/session/mod_session_dbd.c?r1=1409170&r2=1488158&diff_format=h
Reference: http://www.apache.org/dist/httpd/CHANGES_2.4.6

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP
Server before 2.4.5 proceeds with save operations for a session
without considering the dirty flag and the requirement for a new
session ID, which has unspecified impact and remote attack vectors.


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 02:57:55 UTC
CVE-2013-2249 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2249):
  mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server
  before 2.4.5 proceeds with save operations for a session without considering
  the dirty flag and the requirement for a new session ID, which has
  unspecified impact and remote attack vectors.
Comment 2 Sergey Popov gentoo-dev 2013-08-30 10:35:31 UTC
2.4.6 is in tree

According to CVE, 2.2.* is affected :-(

@maintainers: what should we do? 2.4.* is a major update IIRC
Comment 3 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2014-02-19 09:35:24 UTC
Well apache-2.4 still isn't ready for stabilization yet (see "Depends on" bug).

Latest 2.2 apache version is 2.2.26 although I don't know if that version has the fix for this bug.
Comment 4 Dirkjan Ochtman (RETIRED) gentoo-dev 2014-02-24 10:37:46 UTC
mod_session_dbd is new in 2.4, so this doesn't affect 2.2.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2014-08-26 14:36:23 UTC
This only affects the 2.4.6 branch of apache and was fixed in Version 2.4.6. Current no stable version is 2.4.10-r1 in tree.

No GLSA needed as there are no stable versions.