CVE-2004-0488: Buffer Overflow
Stack-based buffer overflow in the sslutiluuencodebinary function in sslutil.c for Apache modssl, when modssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0488?
CVE-2004-0488 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2004-0488?
To fix CVE-2004-0488, upgrade your version of Apache mod_ssl to a secure version beyond 2.0.50.
What systems are affected by CVE-2004-0488?
CVE-2004-0488 affects Apache HTTP Server versions between 2.0.35 and 2.0.50, as well as certain versions of Debian and Red Hat Enterprise Linux.
What does CVE-2004-0488 exploit?
CVE-2004-0488 exploits a stack-based buffer overflow in the ssl_util_uuencode_binary function when mod_ssl is improperly configured.
Can CVE-2004-0488 be exploited remotely?
Yes, CVE-2004-0488 can be exploited remotely through a client certificate with a long subject DN.