CVE-2004-0488
published 2004-07-07CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
37.68%
98.4th percentile
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.50 | 2.0.50 |
| debian | apache2 | < apache2 2.0.50-1 (bookworm) | apache2 2.0.50-1 (bookworm) |
| debian | debian_linux | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit requires FakeBasicAuth to be enabled in mod_ssl configuration; a crafted client certificate with a long subject DN triggers a stack buffer overflow in ssl_util_uuencode_binary (ssl_util.c) ↗
- →The malicious certificate must be signed by a CA that mod_ssl is configured to trust; monitor for client certificates with abnormally long Subject DN fields presented during TLS handshake ↗
- →Vulnerable code is in the ssl_util_uuencode_binary function within ssl_util.c of Apache mod_ssl; target for source-level or binary inspection ↗
- ·Vulnerability is only exploitable when mod_ssl is configured to trust the issuing CA (e.g., SSLCACertificateFile/SSLCACertificatePath set) AND FakeBasicAuth is enabled; deployments without these settings are not at risk ↗
- ·Fixed in Apache mod_ssl version 2.0.50-1; systems running earlier versions with FakeBasicAuth and CA trust configured should be prioritised for patching ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwr4-7j4w-3vv9: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util
ghsa_unreviewed·2022-05-03
CVE-2004-0488 [HIGH] GHSA-cwr4-7j4w-3vv9: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
OSV
CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util
osv·2004-07-07·CVSS 7.5
CVE-2004-0488 [HIGH] CVE-2004-0488: Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Red Hat
mod_ssl ssl_util_uuencode_binary CA issue
vendor_redhat·2004-05-17·CVSS 7.5
CVE-2004-0488 [HIGH] mod_ssl ssl_util_uuencode_binary CA issue
mod_ssl ssl_util_uuencode_binary CA issue
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Debian
CVE-2004-0488: apache2 - Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util...
vendor_debian·2004·CVSS 7.5
CVE-2004-0488 [HIGH] CVE-2004-0488: apache2 - Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util...
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
Scope: local
bookworm: resolved (fixed in 2.0.50-1)
bullseye: resolved (fixed in 2.0.50-1)
forky: resolved (fixed in 2.0.50-1)
sid: resolved (fixed in 2.0.50-1)
trixie: resolved (fixed in 2.0.50-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-0488 mod_ssl ssl_util_uuencode_binary CA issue
bugzilla·2008-01-30·CVSS 7.5
CVE-2004-0488 [HIGH] CVE-2004-0488 mod_ssl ssl_util_uuencode_binary CA issue
CVE-2004-0488 mod_ssl ssl_util_uuencode_binary CA issue
Common Vulnerabilities and Exposures assigned an identifier CVE-2004-0488 to the following vulnerability:
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
References:
http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.html
http://www.debian.org/security/2004/dsa-532
https://bugzilla.fedora.us/show_bug.cgi?id=1888
http://marc.theaimsgroup.com/?l=bugtraq&m=109181600614477&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=109215056218824&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2004:054
http://www.ma
Bugzilla
CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
bugzilla·2005-10-25·CVSS 7.5
CVE-2004-0488 [HIGH] CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
Multiple flaws in Stronghold 4.0 mod_ssl
A stack buffer overflow in mod_ssl. If FakeBasicAuth had been enabled, a
carefully crafted client certificate sent to mod_ssl can cause a stack
overflow. In order to exploit this issue, the malicious certificate would
have to be signed by a Certificate Authority which mod_ssl is configured to
trust. (CVE-2004-0488)
The mod_ssl module, when using the "SSLCipherSuite" directive in directory
or location context, allowed remote clients to bypass intended restrictions
by using any cipher suite that is allowed by the virtual host
configuration. (CVE-2004-0885)
A flaw in mod_ssl triggered if a virtual host was configured using
"SSLVerifyClient optional" and a directive "SSLVerifyClient required"
Bugzilla
CAN-2004-0488 mod_ssl ssl_util_uuencode_binary() stack overflow
bugzilla·2004-06-02
[MEDIUM] CAN-2004-0488 mod_ssl ssl_util_uuencode_binary() stack overflow
CAN-2004-0488 mod_ssl ssl_util_uuencode_binary() stack overflow
A stack-based buffer overflow in the ssl_util_uuencode_binary
function in ssl_util.c for Apache mod_ssl when mod_ssl is
configured to trust the issuing CA, and "FakeBasicAuth" is
being used, could allow remote attackers to execute arbitrary
code via a client certificate with a long subject DN. Public
to full-disclosure on 17May. Fixed Apache 2 CVS 25May
It is quite unlikely that users will have a vulnerable configuration
of Apache, therefore this is of low risk.
CAN-2004-0488 Affects: FC1
CAN-2004-0488 Affects: FC2
Discussion:
Joe, can we please get the fix for mod_ssl: security fix for overflow
in FakeBasicAuth (CVE CAN-2004-0488), for FC1 and 2 which is already
available in 2.0.49-5? I also can find a package fixing thi
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.aschttp://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.htmlhttp://marc.info/?l=bugtraq&m=108567431823750&w=2http://marc.info/?l=bugtraq&m=108619129727620&w=2http://marc.info/?l=bugtraq&m=109181600614477&w=2http://marc.info/?l=bugtraq&m=109215056218824&w=2http://rhn.redhat.com/errata/RHSA-2004-245.htmlhttp://security.gentoo.org/glsa/glsa-200406-05.xmlhttp://www.debian.org/security/2004/dsa-532http://www.mandriva.com/security/advisories?name=MDKSA-2004:054http://www.mandriva.com/security/advisories?name=MDKSA-2004:055http://www.redhat.com/support/errata/RHSA-2004-342.htmlhttp://www.redhat.com/support/errata/RHSA-2004-405.htmlhttp://www.redhat.com/support/errata/RHSA-2005-816.htmlhttp://www.securityfocus.com/bid/10355http://www.trustix.net/errata/2004/0031/https://bugzilla.fedora.us/show_bug.cgi?id=1888https://exchange.xforce.ibmcloud.com/vulnerabilities/16214https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/raa117ef183f0da9b3f46efbeaa66f7622bd68868a450cae4fd8ed594%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11458ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.aschttp://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.htmlhttp://marc.info/?l=bugtraq&m=108567431823750&w=2http://marc.info/?l=bugtraq&m=108619129727620&w=2http://marc.info/?l=bugtraq&m=109181600614477&w=2http://marc.info/?l=bugtraq&m=109215056218824&w=2http://rhn.redhat.com/errata/RHSA-2004-245.htmlhttp://security.gentoo.org/glsa/glsa-200406-05.xmlhttp://www.debian.org/security/2004/dsa-532http://www.mandriva.com/security/advisories?name=MDKSA-2004:054http://www.mandriva.com/security/advisories?name=MDKSA-2004:055http://www.redhat.com/support/errata/RHSA-2004-342.htmlhttp://www.redhat.com/support/errata/RHSA-2004-405.htmlhttp://www.redhat.com/support/errata/RHSA-2005-816.htmlhttp://www.securityfocus.com/bid/10355http://www.trustix.net/errata/2004/0031/https://bugzilla.fedora.us/show_bug.cgi?id=1888https://exchange.xforce.ibmcloud.com/vulnerabilities/16214https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/raa117ef183f0da9b3f46efbeaa66f7622bd68868a450cae4fd8ed594%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11458
2004-07-07
Published