PT-2005-3585 · Apache+2 · Mod Ssl+3

Published

2005-08-30

·

Updated

2023-02-13

·

CVE-2005-2700

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mod ssl versions prior to 2.8.24
Description The issue arises from the improper enforcement of access restrictions in mod ssl when "SSLVerifyClient optional" is set in the global virtual host configuration and "SSLVerifyClient require" is set for a specific location. This allows remote attackers to bypass intended access restrictions by not supplying a client certificate when connecting.
Recommendations For mod ssl versions prior to 2.8.24, update to version 2.8.24 or later to resolve the issue.

Fix

Related Identifiers

CVE-2005-2700
DSA-805-1
DSA-807-1
HPSBUX01232
RHSA-2005:608
RHSA-2005_608

Affected Products

Apache Http Server
Hp-Ux
Red Hat
Mod Ssl