CVE-2008-0555: Input Validation
The ExpandCert function in Apache-SSL before apache1.3.41+ssl1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0555?
CVE-2008-0555 is considered a critical vulnerability as it allows remote attackers to bypass client certificate authentication.
How do I fix CVE-2008-0555?
The recommended fix for CVE-2008-0555 is to upgrade to Apache-SSL version 1.3.41 or higher.
What software is affected by CVE-2008-0555?
CVE-2008-0555 affects Apache-SSL versions before 1.3.41 with SSL version 1.59.
What are the attack vectors for CVE-2008-0555?
Remote attackers can exploit CVE-2008-0555 by crafting a malicious Distinguished Name in a client certificate.
What is the impact of CVE-2008-0555 on system security?
Exploitation of CVE-2008-0555 can lead to unauthorized access by allowing attackers to bypass authentication mechanisms.