CVE Vulnerabilities

CVE-2005-2700

Published: Sep 06, 2005 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using SSLVerifyClient optional in the global virtual host configuration, does not properly enforce SSLVerifyClient require in a per-location context, which allows remote attackers to bypass intended access restrictions.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 2.0.35 (including) 2.0.55 (excluding)
Red Hat Enterprise Linux 3 RedHat httpd-0:2.0.46-46.3.ent *
Red Hat Enterprise Linux 4 RedHat httpd-0:2.0.52-12.2.ent *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Red Hat Stronghold 4 RedHat *
Stronghold 4.0 for Red Hat Enterprise Linux AS (version 2.1) RedHat *
Apache2 Ubuntu dapper *
Apache2 Ubuntu devel *
Apache2 Ubuntu edgy *
Apache2 Ubuntu feisty *
Libapache-mod-ssl Ubuntu dapper *
Libapache-mod-ssl Ubuntu edgy *
Libapache-mod-ssl Ubuntu feisty *

References