PT-2002-2150 · Apache · Apache Mod Ssl

Publicado

2002-11-04

·

Atualizado

2008-09-05

·

CVE-2002-1157

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Apache mod ssl module version 2.8.9 and earlier
Description: A cross-site scripting issue exists in the mod ssl Apache module. This occurs when UseCanonicalName is off and wildcard DNS is enabled, allowing remote attackers to execute scripts as other web site visitors. The attack vector involves the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL.
Recommendations: For Apache mod ssl module version 2.8.9 and earlier, consider updating to a version where this issue is resolved, or as a temporary workaround, enable UseCanonicalName and disable wildcard DNS to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1157
DSA-181

Produtos afetados

Apache Mod Ssl