CVE-2014-8566
published 2014-11-15CVE-2014-8566: The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via…
PriorityP426medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
2.73%
84.5th percentile
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libapache2-mod-auth-mellon | < libapache2-mod-auth-mellon 0.9.1 (bookworm) | libapache2-mod-auth-mellon 0.9.1 (bookworm) |
| oracle | linux | — | — |
| uninett | mod_auth_mellon | <= 0.8.0 | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_auth_mellon: remote memory disclosure flaw
vendor_redhat·2014-11-03·CVSS 6.4
CVE-2014-8566 [MEDIUM] CWE-200 mod_auth_mellon: remote memory disclosure flaw
mod_auth_mellon: remote memory disclosure flaw
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
An information disclosure flaw was found in mod_auth_mellon's session handling that could lead to session overlapping in memory. A remote attacker could potentially use this flaw to obtain data from another user's session.
Debian
CVE-2014-8566: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensit...
vendor_debian·2014·CVSS 6.4
CVE-2014-8566 [MEDIUM] CVE-2014-8566: libapache2-mod-auth-mellon - The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensit...
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
Scope: local
bookworm: resolved (fixed in 0.9.1)
bullseye: resolved (fixed in 0.9.1)
forky: resolved (fixed in 0.9.1)
sid: resolved (fixed in 0.9.1)
trixie: resolved (fixed in 0.9.1)
GHSA
GHSA-4cw9-fccf-p75x: The mod_auth_mellon module before 0
ghsa_unreviewed·2022-05-13
CVE-2014-8566 [MEDIUM] CWE-200 GHSA-4cw9-fccf-p75x: The mod_auth_mellon module before 0
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
OSV
CVE-2014-8566: The mod_auth_mellon module before 0
osv·2014-11-15·CVSS 6.4
CVE-2014-8566 [MEDIUM] CVE-2014-8566: The mod_auth_mellon module before 0
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
No detection rules found.
No public exploits indexed.
Bugzilla
mod_auth_mellon: predictable session cookie in rare cases
bugzilla·2014-10-28·CVSS 6.4
CVE-2014-8566 [MEDIUM] mod_auth_mellon: predictable session cookie in rare cases
mod_auth_mellon: predictable session cookie in rare cases
It was reported that users could receive a predictable session cookie in some cases. This would typically only occur if the server was under very high memory pressure. This could be used to hijack another user's session.
Acknowledgements:
Red Hat would like to thank the mod_auth_mellon team for reporting this issue.
Discussion:
CVE-2014-8566 is not the correct CVE for this issue. In fact, this issue did not receive a CVE, and is related to the following:
https://github.com/UNINETT/mod_auth_mellon/commit/47a767d5f37d1d3a1c004abbf8bb80d1b7eab328
http://jbp.io/2014/01/16/openssl-rand-api/#recommendations-and-patches
It was decided that this could not be used for an attack to force a predictable session cookie to be used.
---
Bugzilla
CVE-2014-8566 mod_auth_mellon: remote memory disclosure flaw
bugzilla·2014-10-26·CVSS 6.4
CVE-2014-8566 [MEDIUM] CVE-2014-8566 mod_auth_mellon: remote memory disclosure flaw
CVE-2014-8566 mod_auth_mellon: remote memory disclosure flaw
mod_auth_mellon provides a SAML 2.0 authentication module for the Apache HTTP Server. A flaw was found that could result in sessions overlapping in memory. A remote attacker could use this flaw to leak memory that possibly contains sensitive information.
Discussion:
Note that it is not totally clear to me that memory is disclosed remotely, it certainly is discolosed to local applications in apache variables.
However such a leak could result in disclosures if the right vartiables are affect, also segfaults have been reported, so perhaps even exploitable in some cases.
---
Acknowledgements:
Red Hat would like to thank the mod_auth_mellon team for reporting this issue. Upstream acknowledges Matthew Slowe as the original report
http://linux.oracle.com/errata/ELSA-2014-1803.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1803.htmlhttp://secunia.com/advisories/62094http://secunia.com/advisories/62125https://github.com/UNINETT/mod_auth_mellon/releases/tag/v0.8.1https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.htmlhttp://linux.oracle.com/errata/ELSA-2014-1803.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1803.htmlhttp://secunia.com/advisories/62094http://secunia.com/advisories/62125https://github.com/UNINETT/mod_auth_mellon/releases/tag/v0.8.1https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.html
2014-11-15
Published