CVE-2004-0700: High severity Mod Ssl Mod Ssl vulnerability
Format string vulnerability in the modproxy hook functions function in sslenginelog.c in modssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssllog function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0700?
CVE-2004-0700 is considered to have a high severity as it may allow remote attackers to execute arbitrary code via format string vulnerabilities.
How do I fix CVE-2004-0700?
To fix CVE-2004-0700, upgrade to a patched version of mod_ssl that is equal to or later than 2.8.19.
Which software versions are affected by CVE-2004-0700?
CVE-2004-0700 affects mod_ssl versions prior to 2.8.19, including various versions like 2.6.2, 2.8.1.2, and others listed in the CVE database.
What attacks can exploit CVE-2004-0700?
Attackers can exploit CVE-2004-0700 to execute arbitrary commands through crafted log messages in HTTPS requests.
Is my system vulnerable to CVE-2004-0700?
You may be vulnerable to CVE-2004-0700 if you are using an affected version of mod_ssl prior to 2.8.19.