PT-2005-4158 · Apache+2 · Apache+3

Publicado

2005-12-12

·

Atualizado

2024-06-15

·

CVE-2005-3357

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache 2.0 versions 2.0 up to 2.0.55
Description The issue is related to a NULL pointer dereference flaw in mod ssl, affecting server configurations with an SSL virtual host that has access control and a custom 400 error document. A remote attacker can send a carefully crafted request to trigger this issue, leading to a crash, which results in a denial of service, particularly when using the worker MPM.
Recommendations For Apache 2.0 versions 2.0 up to 2.0.55, consider disabling the custom 400 error document for SSL virtual hosts with access control as a temporary workaround until a patch is available. Restrict access to the SSL port to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-3357
HPSBUX02172
OPENSUSE-SU-2024:10623-1
RHSA-2006:0159
RHSA-2006_0159

Produtos afetados

Apache
Apache Http Server
Hp-Ux
Red Hat