CVE-2005-1268Off-by-one Error in Apache Http Server

CWE-193Off-by-one Error8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
4.3%
top 11.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 1

Description

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Also affects: Debian Linux 3.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rcfg-8mwj-24g2: Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attacke2022-05-01
CVEList
CVE-2005-1268: Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attacke2005-08-05
OSV
CVE-2005-1268: Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attacke2005-08-05

📋Vendor Advisories

3
Ubuntu
Apache 2 vulnerabilities2005-08-04
Red Hat
security flaw2005-06-08
Debian
CVE-2005-1268: apache2 - Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification c...2005

💬Community

1
Bugzilla
CVE-2005-1268 security flaw2018-08-16
CVE-2005-1268 — Off-by-one Error in Apache Http Server | cvebase