CVE-2005-3357
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
- CVSS 2.0
- 5.4 MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
- EPSS
- 24.29% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- apache/http server
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37791
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.htmlVendor Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://rhn.redhat.com/errata/RHSA-2006-0159.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18307Patch, Vendor Advisory
- http://secunia.com/advisories/18333Patch, Vendor Advisory
- http://secunia.com/advisories/18339Patch, Vendor Advisory
- http://secunia.com/advisories/18340Patch, Vendor Advisory
- http://secunia.com/advisories/18429Patch, Vendor Advisory
- http://secunia.com/advisories/18517Patch, Vendor Advisory
- http://secunia.com/advisories/18585Patch, Vendor Advisory
- http://secunia.com/advisories/18743Patch, Vendor Advisory
- http://secunia.com/advisories/19012Vendor Advisory
- http://secunia.com/advisories/21848Vendor Advisory
- http://secunia.com/advisories/22233Vendor Advisory
- http://secunia.com/advisories/22368Vendor Advisory
- http://secunia.com/advisories/22523Vendor Advisory
- http://secunia.com/advisories/22669Vendor Advisory
- http://secunia.com/advisories/22992Vendor Advisory
- http://secunia.com/advisories/23260Vendor Advisory
- http://secunia.com/advisories/29849Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://securitytracker.com/id?1015447
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102640-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1
- http://support.avaya.com/elmodocs2/security/ASA-2006-250.htm
- http://svn.apache.org/viewcvs?rev=358026&view=rev
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.