Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.0.35 (including) | 2.0.54 (including) |
Red Hat Enterprise Linux 3 | RedHat | httpd-0:2.0.46-46.2.ent | * |
Red Hat Enterprise Linux 4 | RedHat | httpd-0:2.0.52-12.1.ent | * |
Apache2 | Ubuntu | dapper | * |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | edgy | * |
Apache2 | Ubuntu | feisty | * |