CVE-2005-2700
HIGH severity · CVSS 10
10CVSS HIGH
Summary
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)31%
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://people.apache.org/~jorton/CAN-2005-2700.diffAdvisory
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html
- http://marc.info/?l=apache-modssl&m=112569517603897&w=2Advisory
- http://marc.info/?l=bugtraq&m=112604765028607&w=2Advisory
- http://marc.info/?l=bugtraq&m=112870296926652&w=2Advisory
- http://secunia.com/advisories/16700
- http://secunia.com/advisories/16705
- http://secunia.com/advisories/16714