First published: Tue Sep 06 2005(Updated: )
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP server | >=2.0.35<2.0.55 | |
Debian Debian Linux | =3.1 | |
Debian Debian Linux | =3.0 | |
Canonical Ubuntu Linux | =4.10 | |
Canonical Ubuntu Linux | =5.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.