cbcvebase.
CVE-2004-0488
published 2004-07-07

CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may…

PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
37.68%
98.4th percentile
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.502.0.50
debianapache2< apache2 2.0.50-1 (bookworm)apache2 2.0.50-1 (bookworm)
debiandebian_linux
redhatenterprise_linux_server
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires FakeBasicAuth to be enabled in mod_ssl configuration; a crafted client certificate with a long subject DN triggers a stack buffer overflow in ssl_util_uuencode_binary (ssl_util.c)
  • The malicious certificate must be signed by a CA that mod_ssl is configured to trust; monitor for client certificates with abnormally long Subject DN fields presented during TLS handshake
  • Vulnerable code is in the ssl_util_uuencode_binary function within ssl_util.c of Apache mod_ssl; target for source-level or binary inspection
  • ·Vulnerability is only exploitable when mod_ssl is configured to trust the issuing CA (e.g., SSLCACertificateFile/SSLCACertificatePath set) AND FakeBasicAuth is enabled; deployments without these settings are not at risk
  • ·Fixed in Apache mod_ssl version 2.0.50-1; systems running earlier versions with FakeBasicAuth and CA trust configured should be prioritised for patching

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.