Lucene search

K
freebsdFreeBSDE936D612-253F-11DA-BC01-000E0C2E438A
HistoryJul 12, 2005 - 12:00 a.m.

apache -- Certificate Revocation List (CRL) off-by-one vulnerability

2005-07-1200:00:00
vuxml.freebsd.org
19

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.008

Percentile

81.8%

Marc Stern reports an off-by-one vulnerability in within
mod_ssl. The vulnerability lies in mod_ssl’s Certificate
Revocation List (CRL). If Apache is configured to use a
CRL this could allow an attacker to crash a child process
causing a Denial of Service.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchapache< 2.0.54_1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.008

Percentile

81.8%