mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1016832 | |
http://rhn.redhat.com/errata/RHSA-2013-1779.html | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.html | vendor advisory |