Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2004-0700
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0700

Description:
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/16705

UBUNTU
  http://www.ubuntu.com/usn/usn-177-1

REDHAT
  http://www.redhat.com/support/errata/RHSA-2004-405.html
  http://www.redhat.com/support/errata/RHSA-2004-408.html

OSVDB
  7929

MLIST
  http://marc.theaimsgroup.com/?l=apache-modssl&m=109001100906749&w=2

MISC
  http://virulent.siyahsapka.org/
  http://packetstormsecurity.org/0407-advisories/modsslFormat.txt

MANDRAKE
  http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:075

FEDORA

DEBIAN
  http://www.debian.org/security/2004/dsa-532

CONECTIVA
  http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000857

CERT-VN
  303448

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=109005001205991&w=2

BID
  10736


Return to the previous page.