CVE-2004-0009: High severity Apache-SSL Apache-SSL vulnerability
Published Mar 3, 2004
·Updated
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.
Affected Software
1 affected component
Apache-SSL Apache-SSL<=1.3.28_1.52
Event History
Mar 3, 2004
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0009?
CVE-2004-0009 is considered to be a medium severity vulnerability.
2
How do I fix CVE-2004-0009?
To fix CVE-2004-0009, upgrade to Apache-SSL version 1.3.28_1.53 or later.
3
What systems are affected by CVE-2004-0009?
CVE-2004-0009 affects Apache-SSL versions 1.3.28 and earlier, specifically when SSLVerifyClient is set to 1 or 3.
4
What type of attack is possible with CVE-2004-0009?
CVE-2004-0009 allows remote attackers to forge a client certificate using basic authentication.
5
Is CVE-2004-0009 still relevant today?
While CVE-2004-0009 is an older vulnerability, it can still be a concern for systems running outdated Apache-SSL versions.