CVE-2005-2700
published 2005-09-06CVE-2005-2700: ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
30.58%
98.0th percentile
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.55 | 2.0.55 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.0.54-5 (bookworm) | apache2 2.0.54-5 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6h5v-qgqr-fmq8: ssl_engine_kernel
ghsa_unreviewed·2022-05-01
CVE-2005-2700 [HIGH] GHSA-6h5v-qgqr-fmq8: ssl_engine_kernel
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
OSV
CVE-2005-2700: ssl_engine_kernel
osv·2005-09-06·CVSS 10.0
CVE-2005-2700 [CRITICAL] CVE-2005-2700: ssl_engine_kernel
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Ubuntu
Apache 2 vulnerabilities
vendor_ubuntu·2005-09-07
CVE-2005-2728 Apache 2 vulnerabilities
Title: Apache 2 vulnerabilities
Summary: Apache 2 vulnerabilities
Apache did not honour the "SSLVerifyClient require" directive within a
block if the surrounding block contained a
directive "SSLVerifyClient optional". This allowed clients to bypass
client certificate validation on servers with the above configuration.
(CAN-2005-2700)
Filip Sneppe discovered a Denial of Service vulnerability in the byte
range filter handler. By requesting certain large byte ranges, a
remote attacker could cause memory exhaustion in the server.
(CAN-2005-2728)
The updated libapache-mod-ssl also fixes two older Denial of Service
vulnerabilities: A format string error in the ssl_log() function which
could be exploited to crash the server (CAN-2004-0700), and a flaw in
the SSL cipher negotiation which could
Red Hat
security flaw
vendor_redhat·2005-08-30·CVSS 10.0
CVE-2005-2700 [CRITICAL] security flaw
security flaw
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Debian
CVE-2005-2700: apache2 - ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient option...
vendor_debian·2005·CVSS 10.0
CVE-2005-2700 [CRITICAL] CVE-2005-2700: apache2 - ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient option...
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Scope: local
bookworm: resolved (fixed in 2.0.54-5)
bullseye: resolved (fixed in 2.0.54-5)
forky: resolved (fixed in 2.0.54-5)
sid: resolved (fixed in 2.0.54-5)
trixie: resolved (fixed in 2.0.54-5)
No detection rules found.
Bugzilla
CVE-2005-2700 security flaw
bugzilla·2018-08-16·CVSS 10.0
CVE-2005-2700 [CRITICAL] CVE-2005-2700 security flaw
CVE-2005-2700 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
Bugzilla
CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
bugzilla·2005-10-25·CVSS 7.5
CVE-2004-0488 [HIGH] CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
CVE-2004-0488 mod_ssl flaws (CVE-2004-0885 CVE-2005-2700)
Multiple flaws in Stronghold 4.0 mod_ssl
A stack buffer overflow in mod_ssl. If FakeBasicAuth had been enabled, a
carefully crafted client certificate sent to mod_ssl can cause a stack
overflow. In order to exploit this issue, the malicious certificate would
have to be signed by a Certificate Authority which mod_ssl is configured to
trust. (CVE-2004-0488)
The mod_ssl module, when using the "SSLCipherSuite" directive in directory
or location context, allowed remote clients to bypass intended restrictions
by using any cipher suite that is allowed by the virtual host
configuration. (CVE-2004-0885)
A flaw in mod_ssl triggered if a virtual host was configured using
"SSLVerifyClient optional" and a directive "SSLVerifyClient required"
http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://marc.info/?l=apache-modssl&m=112569517603897&w=2http://marc.info/?l=bugtraq&m=112604765028607&w=2http://marc.info/?l=bugtraq&m=112870296926652&w=2http://people.apache.org/~jorton/CAN-2005-2700.diffhttp://secunia.com/advisories/16700http://secunia.com/advisories/16705http://secunia.com/advisories/16714http://secunia.com/advisories/16743http://secunia.com/advisories/16746http://secunia.com/advisories/16748http://secunia.com/advisories/16753http://secunia.com/advisories/16754http://secunia.com/advisories/16769http://secunia.com/advisories/16771http://secunia.com/advisories/16789http://secunia.com/advisories/16864http://secunia.com/advisories/16956http://secunia.com/advisories/17088http://secunia.com/advisories/17288http://secunia.com/advisories/17311http://secunia.com/advisories/17813http://secunia.com/advisories/19072http://secunia.com/advisories/19073http://secunia.com/advisories/21848http://secunia.com/advisories/22523http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://www.debian.org/security/2005/dsa-805http://www.debian.org/security/2005/dsa-807http://www.gentoo.org/security/en/glsa/glsa-200509-12.xmlhttp://www.kb.cert.org/vuls/id/744929http://www.mandriva.com/security/advisories?name=MDKSA-2005:161http://www.novell.com/linux/security/advisories/2005_51_apache2.htmlhttp://www.novell.com/linux/security/advisories/2005_52_apache2.htmlhttp://www.osvdb.org/19188http://www.redhat.com/support/errata/RHSA-2005-608.htmlhttp://www.redhat.com/support/errata/RHSA-2005-773.htmlhttp://www.redhat.com/support/errata/RHSA-2005-816.htmlhttp://www.securityfocus.com/bid/14721http://www.ubuntu.com/usn/usn-177-1http://www.vupen.com/english/advisories/2005/1625http://www.vupen.com/english/advisories/2005/2659http://www.vupen.com/english/advisories/2006/0789http://www.vupen.com/english/advisories/2006/4207http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167195https://lists.apache.org/thread.html/117bc3f09847ebf020b1bb70301ebcc105ddc446856150b63f37f8eb%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5b1e7d66c5adf286f14f6cc0f857b6fca107444f68aed9e70eedab47%40%3Cdev.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.opensuse.org/opensuse-security-announce/2006-09/msg00016.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10416http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://marc.info/?l=apache-modssl&m=112569517603897&w=2http://marc.info/?l=bugtraq&m=112604765028607&w=2http://marc.info/?l=bugtraq&m=112870296926652&w=2http://people.apache.org/~jorton/CAN-2005-2700.diffhttp://secunia.com/advisories/16700http://secunia.com/advisories/16705http://secunia.com/advisories/16714http://secunia.com/advisories/16743http://secunia.com/advisories/16746http://secunia.com/advisories/16748http://secunia.com/advisories/16753http://secunia.com/advisories/16754http://secunia.com/advisories/16769http://secunia.com/advisories/16771http://secunia.com/advisories/16789http://secunia.com/advisories/16864http://secunia.com/advisories/16956http://secunia.com/advisories/17088http://secunia.com/advisories/17288http://secunia.com/advisories/17311http://secunia.com/advisories/17813http://secunia.com/advisories/19072http://secunia.com/advisories/19073http://secunia.com/advisories/21848http://secunia.com/advisories/22523http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1http://support.avaya.com/elmodocs2/security/ASA-2006-081.htmhttp://www.debian.org/security/2005/dsa-805http://www.debian.org/security/2005/dsa-807http://www.gentoo.org/security/en/glsa/glsa-200509-12.xmlhttp://www.kb.cert.org/vuls/id/744929http://www.mandriva.com/security/advisories?name=MDKSA-2005:161http://www.novell.com/linux/security/advisories/2005_51_apache2.htmlhttp://www.novell.com/linux/security/advisories/2005_52_apache2.html
+ 28 more references
2005-09-06
Published