Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
References
Configurations
History
20 Nov 2024, 23:39
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-031.0.txt - Broken Link | |
References | () http://archives.neohapsis.com/archives/bugtraq/2002-06/0350.html - Broken Link | |
References | () http://archives.neohapsis.com/archives/hp/2002-q3/0018.html - Broken Link | |
References | () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000504 - Broken Link | |
References | () http://marc.info/?l=bugtraq&m=102513970919836&w=2 - Mailing List | |
References | () http://marc.info/?l=bugtraq&m=102563469326072&w=2 - Mailing List, Patch | |
References | () http://marc.info/?l=vuln-dev&m=102477330617604&w=2 - Mailing List | |
References | () http://rhn.redhat.com/errata/RHSA-2002-164.html - Broken Link | |
References | () http://www.debian.org/security/2002/dsa-135 - Broken Link | |
References | () http://www.iss.net/security_center/static/9415.php - Broken Link | |
References | () http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-048.php - Broken Link | |
References | () http://www.novell.com/linux/security/advisories/2002_028_mod_ssl.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2002-134.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2002-135.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2002-136.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2002-146.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2003-106.html - Broken Link | |
References | () http://www.securityfocus.com/bid/5084 - Broken Link, Third Party Advisory, VDB Entry |
02 Feb 2024, 02:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:modssl:mod_ssl:*:*:*:*:*:*:*:* | |
First Time |
Modssl
Modssl mod Ssl |
|
CWE | CWE-193 | |
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
References | (VULN-DEV) http://marc.info/?l=vuln-dev&m=102477330617604&w=2 - Mailing List | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-146.html - Broken Link | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-135.html - Broken Link | |
References | (XF) http://www.iss.net/security_center/static/9415.php - Broken Link | |
References | (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000504 - Broken Link | |
References | (HP) http://archives.neohapsis.com/archives/hp/2002-q3/0018.html - Broken Link | |
References | (REDHAT) http://rhn.redhat.com/errata/RHSA-2002-164.html - Broken Link | |
References | (SUSE) http://www.novell.com/linux/security/advisories/2002_028_mod_ssl.html - Broken Link | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-134.html - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/5084 - Broken Link, Third Party Advisory, VDB Entry | |
References | (ENGARDE) http://marc.info/?l=bugtraq&m=102563469326072&w=2 - Mailing List, Patch | |
References | (BUGTRAQ) http://marc.info/?l=bugtraq&m=102513970919836&w=2 - Mailing List | |
References | (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2002-06/0350.html - Broken Link | |
References | (CALDERA) ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-031.0.txt - Broken Link | |
References | (DEBIAN) http://www.debian.org/security/2002/dsa-135 - Broken Link | |
References | (MANDRAKE) http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-048.php - Broken Link | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2003-106.html - Broken Link | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2002-136.html - Broken Link |
Information
Published : 2002-07-11 04:00
Updated : 2024-11-20 23:39
NVD link : CVE-2002-0653
Mitre link : CVE-2002-0653
CVE.ORG link : CVE-2002-0653
JSON object : View
Products Affected
modssl
- mod_ssl
CWE
CWE-193
Off-by-one Error