Commit 41f59653 authored by Joe Orton's avatar Joe Orton
Browse files

Backport from HEAD:

  * modules/ssl/ssl_engine_kernel.c (ssl_hook_UserCheck): Fix buffer
  overflow in FakeBasicAuth code if client's subject DN exceeds 6K in
  length (CVE CAN-2004-0488); switch to using apr-util base64 encoder
  functions.

  * modules/ssl/ssl_engine_init.c (ssl_init_Engine): Log the OpenSSL
  error stack contents if engine load/init fails.

  * modules/ssl/ssl_engine_log.c (ssl_log_ssl_error): Use %lu to print
  an unsigned long.

  * modules/ssl/ssl_engine_log.c (ssl_log_annotate, ssl_log_annotation,
  ssl_log_ssl_error): const-ify annotation strings and simplify
  ssl_log_annotation.

Reviewed by: Andr�� Malo, Jeff Trawick


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/APACHE_2_0_BRANCH@103867 13f79535-47bb-0310-9956-ffa450edef68
parent 489feed4
Loading
Loading
Loading
Loading
+8 −0
Changes for CHANGES: 8 added lines, 0 removed lines.
Original line number Diff line number Diff line
Changes with Apache 2.0.50
  *) SECURITY: CAN-2004-0488 (cve.mitre.org)
     mod_ssl: Fix a buffer overflow in the FakeBasicAuth code for a
     (trusted) client certificate subject DN which exceeds 6K in length.
     [Joe Orton]
  *) mod_ssl: Log the errors returned on failure to load or initialize
     a crypto accelerator engine.  [Joe Orton]
  *) Allow RequestHeader directives to be conditional. PR 27951.
     [Vincent Deffontaines <vincent gryzor.com>, André Malo]
+1 −14
Changes for STATUS: 1 added line, 14 removed lines.
Original line number Diff line number Diff line
APACHE 2.0 STATUS:                                              -*-text-*-
Last modified at [$Date: 2004/06/06 22:19:38 $]
Last modified at [$Date: 2004/06/07 10:18:36 $]

Release:

@@ -77,24 +77,11 @@ PATCHES TO BACKPORT FROM 2.1
       PR: 29318
       +1: jorton, trawick, nd

    *) mod_ssl: Fix buffer overflow in FakeBasicAuth support (CVE CAN-2004-0488)
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_kernel.c?r1=1.105&r2=1.106
       +1: jorton, nd, trawick

    *) mod_ssl: Remove some unused functions (after CAN-2004-0488 fix is applied)
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_util.c?r1=1.46&r2=1.47
       +1: jorton, nd
       trawick: need changes to mod_ssl.h to remove prototypes for those removed functions

    *) mod_ssl: Fix a GCC strict-aliasing warning.
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_config.c?r1=1.90&r2=1.91
       +1: jorton, nd, trawick

    *) mod_ssl: Cleanups and fixes for mod_ssl logging.
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_init.c?r1=1.124&r2=1.125
       http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_log.c?r1=1.31&r2=1.28
       +1: jorton, nd, trawick

    *) Enable the option to support anonymous shared memory in mod_ldap.
       This makes the cache work on Linux again.
       modules/experimental/util_ldap.c r1.30
+4 −5
Changes for modules/ssl/ssl_engine_config.c: 4 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -39,12 +39,11 @@ SSLModConfigRec *ssl_config_global_create(server_rec *s)
{
    apr_pool_t *pool = s->process->pool;
    SSLModConfigRec *mc;
    void *vmc;

    apr_pool_userdata_get((void **)&mc, SSL_MOD_CONFIG_KEY,
                          pool);

    if (mc) {
        return mc; /* reused for lifetime of the server */
    apr_pool_userdata_get(&vmc, SSL_MOD_CONFIG_KEY, pool);
    if (vmc) {
        return vmc; /* reused for lifetime of the server */
    }

    /*
+2 −0
Changes for modules/ssl/ssl_engine_init.c: 2 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -326,6 +326,7 @@ void ssl_init_Engine(server_rec *s, apr_pool_t *p)
            ap_log_error(APLOG_MARK, APLOG_ERR, 0, s,
                         "Init: Failed to load Crypto Device API `%s'",
                         mc->szCryptoDevice);
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
            ssl_die();
        }

@@ -337,6 +338,7 @@ void ssl_init_Engine(server_rec *s, apr_pool_t *p)
            ap_log_error(APLOG_MARK, APLOG_ERR, 0, s,
                         "Init: Failed to enable Crypto Device API `%s'",
                         mc->szCryptoDevice);
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
            ssl_die();
        }

+8 −7
Changes for modules/ssl/ssl_engine_kernel.c: 8 added lines, 7 removed lines.
Original line number Diff line number Diff line
@@ -793,7 +793,6 @@ int ssl_hook_UserCheck(request_rec *r)
    SSLConnRec *sslconn = myConnConfig(r->connection);
    SSLSrvConfigRec *sc = mySrvConfig(r->server);
    SSLDirConfigRec *dc = myDirConfig(r);
    char buf1[MAX_STRING_LEN], buf2[MAX_STRING_LEN];
    char *clientdn;
    const char *auth_line, *username, *password;

@@ -872,14 +871,16 @@ int ssl_hook_UserCheck(request_rec *r)
     * adding the string "xxj31ZMTZzkVA" as the password in the user file.
     * This is just the crypted variant of the word "password" ;-)
     */
    apr_snprintf(buf1, sizeof(buf1), "%s:password", clientdn);
    ssl_util_uuencode(buf2, buf1, FALSE);

    apr_snprintf(buf1, sizeof(buf1), "Basic %s", buf2);
    apr_table_set(r->headers_in, "Authorization", buf1);
    auth_line = apr_pstrcat(r->pool, "Basic ", 
                            ap_pbase64encode(r->pool, 
                                             apr_pstrcat(r->pool, clientdn, 
                                                         ":password", NULL)),
                            NULL);
    apr_table_set(r->headers_in, "Authorization", auth_line);

    ap_log_error(APLOG_MARK, APLOG_INFO, 0, r->server,
                 "Faking HTTP Basic Auth header: \"Authorization: %s\"", buf1);
                 "Faking HTTP Basic Auth header: \"Authorization: %s\"",
                 auth_line);

    return DECLINED;
}
Loading