CVE Vulnerabilities

CVE-2004-0700

Published: Jul 27, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

Affected Software

NameVendorStart VersionEnd Version
Mod_sslMod_ssl2.3.11 (including)2.3.11 (including)
Mod_sslMod_ssl2.4.0 (including)2.4.0 (including)
Mod_sslMod_ssl2.4.1 (including)2.4.1 (including)
Mod_sslMod_ssl2.4.2 (including)2.4.2 (including)
Mod_sslMod_ssl2.4.3 (including)2.4.3 (including)
Mod_sslMod_ssl2.4.4 (including)2.4.4 (including)
Mod_sslMod_ssl2.4.5 (including)2.4.5 (including)
Mod_sslMod_ssl2.4.6 (including)2.4.6 (including)
Mod_sslMod_ssl2.4.7 (including)2.4.7 (including)
Mod_sslMod_ssl2.4.8 (including)2.4.8 (including)
Mod_sslMod_ssl2.4.9 (including)2.4.9 (including)
Mod_sslMod_ssl2.4.10 (including)2.4.10 (including)
Mod_sslMod_ssl2.5.0 (including)2.5.0 (including)
Mod_sslMod_ssl2.5.1 (including)2.5.1 (including)
Mod_sslMod_ssl2.6.0 (including)2.6.0 (including)
Mod_sslMod_ssl2.6.1 (including)2.6.1 (including)
Mod_sslMod_ssl2.6.2 (including)2.6.2 (including)
Mod_sslMod_ssl2.6.3 (including)2.6.3 (including)
Mod_sslMod_ssl2.6.4 (including)2.6.4 (including)
Mod_sslMod_ssl2.6.5 (including)2.6.5 (including)
Mod_sslMod_ssl2.6.6 (including)2.6.6 (including)
Mod_sslMod_ssl2.7.0 (including)2.7.0 (including)
Mod_sslMod_ssl2.7.1 (including)2.7.1 (including)
Mod_sslMod_ssl2.8.0 (including)2.8.0 (including)
Mod_sslMod_ssl2.8.1 (including)2.8.1 (including)
Mod_sslMod_ssl2.8.1.2 (including)2.8.1.2 (including)
Mod_sslMod_ssl2.8.2 (including)2.8.2 (including)
Mod_sslMod_ssl2.8.3 (including)2.8.3 (including)
Mod_sslMod_ssl2.8.4 (including)2.8.4 (including)
Mod_sslMod_ssl2.8.5 (including)2.8.5 (including)
Mod_sslMod_ssl2.8.5.1 (including)2.8.5.1 (including)
Mod_sslMod_ssl2.8.5.2 (including)2.8.5.2 (including)
Mod_sslMod_ssl2.8.6 (including)2.8.6 (including)
Mod_sslMod_ssl2.8.7 (including)2.8.7 (including)
Mod_sslMod_ssl2.8.8 (including)2.8.8 (including)
Mod_sslMod_ssl2.8.9 (including)2.8.9 (including)
Mod_sslMod_ssl2.8.10 (including)2.8.10 (including)
Mod_sslMod_ssl2.8.12 (including)2.8.12 (including)
Mod_sslMod_ssl2.8.14 (including)2.8.14 (including)
Mod_sslMod_ssl2.8.15 (including)2.8.15 (including)
Mod_sslMod_ssl2.8.16 (including)2.8.16 (including)
Mod_sslMod_ssl2.8.17 (including)2.8.17 (including)
Mod_sslMod_ssl2.8.18 (including)2.8.18 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Network Proxy v 4.2 (RHEL 3)RedHatjabberd-0:2.0s10-3.37.rhn*
Red Hat Network Proxy v 4.2 (RHEL 3)RedHatrhn-apache-0:1.3.27-36.rhn.rhel3*
Red Hat Network Proxy v 4.2 (RHEL 3)RedHatrhn-modperl-0:1.29-16.rhel3*
Red Hat Network Proxy v 4.2 (RHEL 4)RedHatjabberd-0:2.0s10-3.38.rhn*
Red Hat Network Proxy v 4.2 (RHEL 4)RedHatrhn-apache-0:1.3.27-36.rhn.rhel4*
Red Hat Network Proxy v 4.2 (RHEL 4)RedHatrhn-modperl-0:1.29-16.rhel4*
Red Hat Stronghold 4RedHat*

References