PT-2005-3585 · Apache+2 · Mod Ssl+3
Published
2005-08-30
·
Updated
2023-02-13
·
CVE-2005-2700
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
mod ssl versions prior to 2.8.24
Description
The issue arises from the improper enforcement of access restrictions in mod ssl when "SSLVerifyClient optional" is set in the global virtual host configuration and "SSLVerifyClient require" is set for a specific location. This allows remote attackers to bypass intended access restrictions by not supplying a client certificate when connecting.
Recommendations
For mod ssl versions prior to 2.8.24, update to version 2.8.24 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Hp-Ux
Red Hat
Mod Ssl