Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2003-0192
HistoryAug 18, 2003 - 4:00 a.m.

CVE-2003-0192

2003-08-1804:00:00
Debian Security Bug Tracker
security-tracker.debian.org
17

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

0.012 Low

EPSS

Percentile

85.0%

Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle “certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one,” which could cause Apache to use the weak ciphersuite.

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

0.012 Low

EPSS

Percentile

85.0%

Related for DEBIANCVE:CVE-2003-0192