CVE Vulnerabilities

CVE-2004-0885

Published: Nov 03, 2004 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the SSLCipherSuite directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 2.0.35 (including) 2.0.35 (including)
Http_server Apache 2.0.36 (including) 2.0.36 (including)
Http_server Apache 2.0.37 (including) 2.0.37 (including)
Http_server Apache 2.0.38 (including) 2.0.38 (including)
Http_server Apache 2.0.39 (including) 2.0.39 (including)
Http_server Apache 2.0.40 (including) 2.0.40 (including)
Http_server Apache 2.0.41 (including) 2.0.41 (including)
Http_server Apache 2.0.42 (including) 2.0.42 (including)
Http_server Apache 2.0.43 (including) 2.0.43 (including)
Http_server Apache 2.0.44 (including) 2.0.44 (including)
Http_server Apache 2.0.45 (including) 2.0.45 (including)
Http_server Apache 2.0.46 (including) 2.0.46 (including)
Http_server Apache 2.0.47 (including) 2.0.47 (including)
Http_server Apache 2.0.48 (including) 2.0.48 (including)
Http_server Apache 2.0.49 (including) 2.0.49 (including)
Http_server Apache 2.0.50 (including) 2.0.50 (including)
Http_server Apache 2.0.51 (including) 2.0.51 (including)
Http_server Apache 2.0.52 (including) 2.0.52 (including)

References