10

CVE-2005-2700

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 2.0.35 < 2.0.55
DebianDebian Linux Version3.0
DebianDebian Linux Version3.1
CanonicalUbuntu Linux Version4.10
CanonicalUbuntu Linux Version5.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.69% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
http://marc.info/?l=bugtraq&m=112604765028607&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=bugtraq&m=112870296926652&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.kb.cert.org/vuls/id/744929
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/14721
Third Party Advisory
VDB Entry