Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mod_ssl | Mod_ssl | 2.3.11 (including) | 2.3.11 (including) |
Mod_ssl | Mod_ssl | 2.4.0 (including) | 2.4.0 (including) |
Mod_ssl | Mod_ssl | 2.4.1 (including) | 2.4.1 (including) |
Mod_ssl | Mod_ssl | 2.4.2 (including) | 2.4.2 (including) |
Mod_ssl | Mod_ssl | 2.4.3 (including) | 2.4.3 (including) |
Mod_ssl | Mod_ssl | 2.4.4 (including) | 2.4.4 (including) |
Mod_ssl | Mod_ssl | 2.4.5 (including) | 2.4.5 (including) |
Mod_ssl | Mod_ssl | 2.4.6 (including) | 2.4.6 (including) |
Mod_ssl | Mod_ssl | 2.4.7 (including) | 2.4.7 (including) |
Mod_ssl | Mod_ssl | 2.4.8 (including) | 2.4.8 (including) |
Mod_ssl | Mod_ssl | 2.4.9 (including) | 2.4.9 (including) |
Mod_ssl | Mod_ssl | 2.4.10 (including) | 2.4.10 (including) |
Mod_ssl | Mod_ssl | 2.5.0 (including) | 2.5.0 (including) |
Mod_ssl | Mod_ssl | 2.5.1 (including) | 2.5.1 (including) |
Mod_ssl | Mod_ssl | 2.6.0 (including) | 2.6.0 (including) |
Mod_ssl | Mod_ssl | 2.6.1 (including) | 2.6.1 (including) |
Mod_ssl | Mod_ssl | 2.6.2 (including) | 2.6.2 (including) |
Mod_ssl | Mod_ssl | 2.6.3 (including) | 2.6.3 (including) |
Mod_ssl | Mod_ssl | 2.6.4 (including) | 2.6.4 (including) |
Mod_ssl | Mod_ssl | 2.6.5 (including) | 2.6.5 (including) |
Mod_ssl | Mod_ssl | 2.6.6 (including) | 2.6.6 (including) |
Mod_ssl | Mod_ssl | 2.7.0 (including) | 2.7.0 (including) |
Mod_ssl | Mod_ssl | 2.7.1 (including) | 2.7.1 (including) |
Mod_ssl | Mod_ssl | 2.8.0 (including) | 2.8.0 (including) |
Mod_ssl | Mod_ssl | 2.8.1 (including) | 2.8.1 (including) |
Mod_ssl | Mod_ssl | 2.8.1.2 (including) | 2.8.1.2 (including) |
Mod_ssl | Mod_ssl | 2.8.2 (including) | 2.8.2 (including) |
Mod_ssl | Mod_ssl | 2.8.3 (including) | 2.8.3 (including) |
Mod_ssl | Mod_ssl | 2.8.4 (including) | 2.8.4 (including) |
Mod_ssl | Mod_ssl | 2.8.5 (including) | 2.8.5 (including) |
Mod_ssl | Mod_ssl | 2.8.5.1 (including) | 2.8.5.1 (including) |
Mod_ssl | Mod_ssl | 2.8.5.2 (including) | 2.8.5.2 (including) |
Mod_ssl | Mod_ssl | 2.8.6 (including) | 2.8.6 (including) |
Mod_ssl | Mod_ssl | 2.8.7 (including) | 2.8.7 (including) |
Mod_ssl | Mod_ssl | 2.8.8 (including) | 2.8.8 (including) |
Mod_ssl | Mod_ssl | 2.8.9 (including) | 2.8.9 (including) |
Mod_ssl | Mod_ssl | 2.8.10 (including) | 2.8.10 (including) |
Mod_ssl | Mod_ssl | 2.8.12 (including) | 2.8.12 (including) |
Mod_ssl | Mod_ssl | 2.8.14 (including) | 2.8.14 (including) |
Mod_ssl | Mod_ssl | 2.8.15 (including) | 2.8.15 (including) |
Mod_ssl | Mod_ssl | 2.8.16 (including) | 2.8.16 (including) |
Mod_ssl | Mod_ssl | 2.8.17 (including) | 2.8.17 (including) |
Mod_ssl | Mod_ssl | 2.8.18 (including) | 2.8.18 (including) |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Enterprise Linux WS version 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Red Hat Network Proxy v 4.2 (RHEL 3) | RedHat | jabberd-0:2.0s10-3.37.rhn | * |
Red Hat Network Proxy v 4.2 (RHEL 3) | RedHat | rhn-apache-0:1.3.27-36.rhn.rhel3 | * |
Red Hat Network Proxy v 4.2 (RHEL 3) | RedHat | rhn-modperl-0:1.29-16.rhel3 | * |
Red Hat Network Proxy v 4.2 (RHEL 4) | RedHat | jabberd-0:2.0s10-3.38.rhn | * |
Red Hat Network Proxy v 4.2 (RHEL 4) | RedHat | rhn-apache-0:1.3.27-36.rhn.rhel4 | * |
Red Hat Network Proxy v 4.2 (RHEL 4) | RedHat | rhn-modperl-0:1.29-16.rhel4 | * |
Red Hat Stronghold 4 | RedHat | * |