HIGH · 7.5

CVE-2004-1082

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

Vulnerability Description

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ApacheHttp Server1.3
AppleApache Mod Digest AppleAll versions
AvayaCommunication Manager1.1
AvayaIntuity Audix LxAll versions
HpVirtualvault4.5
HpWebproxya.02.00
IbmHttp Server1.3.19
AvayaMn100All versions
AvayaNetwork RoutingAll versions
AvayaModular Messaging Message Storage Server1.1
OpenbsdOpenbsd3.4
ScoOpenserver5.0.6
SunSolaris8.0
SunSunos5.8

References

FAQ

What is CVE-2004-1082?

CVE-2004-1082 is a vulnerability with a CVSS score of 7.5 (HIGH). mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

How severe is CVE-2004-1082?

CVE-2004-1082 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1082?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Apple Apache Mod Digest Apple, Avaya Communication Manager, Avaya Intuity Audix Lx, Hp Virtualvault.