Описание
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.0.55-4ubuntu2.2 |
devel | released | 2.2.4-3 |
edgy | released | 2.0.55-4ubuntu4.1 |
feisty | released | 2.2.3-3.2ubuntu0.1 |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | released | 2.8.25-1 |
devel | DNE | |
edgy | released | 2.8.25-1 |
feisty | released | 2.8.25-1 |
upstream | needs-triage |
Показывать по
EPSS
10 Critical
CVSS2
Связанные уязвимости
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyCli ...
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
EPSS
10 Critical
CVSS2