Format string vulnerability in the mod_proxy hook functions function in...
Vulnerability Description
Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0700
Credits & Attribution
No credits recorded in the NVD database.
References
- http://virulent.siyahsapka.org/
- http://www.osvdb.org/7929
- http://www.ubuntu.com/usn/usn-177-1
- http://www.securityfocus.com/bid/10736
- http://www.redhat.com/support/errata/RHSA-2004-405.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16705
- http://packetstormsecurity.org/0407-advisories/modsslFormat.txt
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000857
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:075
- http://www.debian.org/security/2004/dsa-532
- http://www.redhat.com/support/errata/RHSA-2004-408.html
- https://bugzilla.fedora.us/show_bug.cgi?id=1888
- http://marc.info/?l=apache-modssl&m=109001100906749&w=2
- http://www.kb.cert.org/vuls/id/303448
- http://marc.info/?l=bugtraq&m=109005001205991&w=2
Affected Vendor
mod ssl
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.