CVE-2005-2700
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 30.58% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlBroken Link
- http://marc.info/?l=apache-modssl&m=112569517603897&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=112604765028607&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=112870296926652&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://people.apache.org/~jorton/CAN-2005-2700.diffVendor Advisory
- http://secunia.com/advisories/16700Not Applicable
- http://secunia.com/advisories/16705Not Applicable
- http://secunia.com/advisories/16714Not Applicable
- http://secunia.com/advisories/16743Not Applicable
- http://secunia.com/advisories/16746Not Applicable
- http://secunia.com/advisories/16748Not Applicable
- http://secunia.com/advisories/16753Not Applicable
- http://secunia.com/advisories/16754Not Applicable
- http://secunia.com/advisories/16769Not Applicable
- http://secunia.com/advisories/16771Not Applicable
- http://secunia.com/advisories/16789Not Applicable
- http://secunia.com/advisories/16864Not Applicable
- http://secunia.com/advisories/16956Not Applicable
- http://secunia.com/advisories/17088Not Applicable
- http://secunia.com/advisories/17288Not Applicable
- http://secunia.com/advisories/17311Not Applicable
- http://secunia.com/advisories/17813Not Applicable
- http://secunia.com/advisories/19072Not Applicable
- http://secunia.com/advisories/19073Not Applicable
- http://secunia.com/advisories/21848Not Applicable
- http://secunia.com/advisories/22523Not Applicable
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmThird Party Advisory
- http://www.debian.org/security/2005/dsa-805Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.