Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-0555

Опубликовано: 04 апр. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

released

1.3.41+ssl_1.59

Показывать по

Ссылки на источники

EPSS

Процентиль: 66%
0.00524
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.

debian
больше 17 лет назад

The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 do ...

github
больше 3 лет назад

The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.

EPSS

Процентиль: 66%
0.00524
Низкий

7.5 High

CVSS2