Lucene search

K
httpdApache Team FoundationHTTPD:E5BCF7FEE4CAFF4CFFF0CE85C63F8ACE
HistoryOct 14, 2005 - 12:00 a.m.

Apache Httpd < 2.0.55 : Malicious CRL off-by-one

2005-10-1400:00:00
Apache Team Foundation
httpd.apache.org
14

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.008

Percentile

81.8%

An off-by-one stack overflow was discovered in the mod_ssl CRL verification callback. In order to exploit this issue the Apache server would need to be configured to use a malicious certificate revocation list (CRL)

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.008

Percentile

81.8%