Race Condition During Access to Alternate Channel |
Weakness ID: 421 (Weakness Base) | Status: Draft |
Description Summary
The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.
Extended Description
This creates a race condition that allows an attacker to access the channel before the authorized user does.
Reference | Description |
---|---|
CVE-1999-0351 | FTP "Pizza Thief" vulnerability. Attacker can connect to a port that was intended for use by another client. |
CVE-2003-0230 | Product creates Windows named pipe during authentication that another attacker can hijack by connecting to it. |
Protect access to resources. Enforce an authentication check on every transaction. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 362 | Race Condition | Development Concepts699 Research Concepts1000 |
ChildOf | ![]() | 420 | Unprotected Alternate Channel | Development Concepts (primary)699 Research Concepts (primary)1000 |
ChildOf | ![]() | 634 | Weaknesses that Affect System Processes | Resource-specific Weaknesses (primary)631 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Alternate Channel Race Condition |
Blake Watts. "Discovering and Exploiting Named Pipe Security Flaws for Fun and Profit". April 2002. <http://www.blakewatts.com/namedpipepaper.html>. |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Potential Mitigations, Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Observed Example, Other Notes, Taxonomy Mappings, Type | ||||
2008-10-14 | CWE Content Team | MITRE | Internal | |
updated Description | ||||
2009-01-12 | CWE Content Team | MITRE | Internal | |
updated References | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-04-11 | Alternate Channel Race Condition | |||