Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.11039
Kategorie:Web Servers
Titel:Apache HTTP Server 'mod_ssl' Off By One Vulnerability
Zusammenfassung:The remote host is using a version of mod_ssl which is; older than 2.8.10.;; This version is vulnerable to an off by one buffer overflow which may allow a user with; write access to .htaccess files to execute arbitrary code on the system with permissions; of the web server.
Beschreibung:Summary:
The remote host is using a version of mod_ssl which is
older than 2.8.10.

This version is vulnerable to an off by one buffer overflow which may allow a user with
write access to .htaccess files to execute arbitrary code on the system with permissions
of the web server.

Solution:
Update to version 2.8.10 or later.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2002-0653
BugTraq ID: 5084
http://www.securityfocus.com/bid/5084
Bugtraq: 20020624 Apache mod_ssl off-by-one vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=102513970919836&w=2
Bugtraq: 20020628 TSL-2002-0058 - apache/mod_ssl (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2002-06/0350.html
Caldera Security Advisory: CSSA-2002-031.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-031.0.txt
Conectiva Linux advisory: CLA-2002:504
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000504
Debian Security Information: DSA-135 (Google Search)
http://www.debian.org/security/2002/dsa-135
En Garde Linux Advisory: ESA-20020702-017
http://marc.info/?l=bugtraq&m=102563469326072&w=2
HPdes Security Advisory: HPSBTL0207-052
http://archives.neohapsis.com/archives/hp/2002-q3/0018.html
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-048.php
http://www.redhat.com/support/errata/RHSA-2002-134.html
http://www.redhat.com/support/errata/RHSA-2002-135.html
http://www.redhat.com/support/errata/RHSA-2002-136.html
http://www.redhat.com/support/errata/RHSA-2002-146.html
RedHat Security Advisories: RHSA-2002:164
http://rhn.redhat.com/errata/RHSA-2002-164.html
http://www.redhat.com/support/errata/RHSA-2003-106.html
SuSE Security Announcement: SuSE-SA:2002:028 (Google Search)
http://www.novell.com/linux/security/advisories/2002_028_mod_ssl.html
http://marc.info/?l=vuln-dev&m=102477330617604&w=2
http://www.iss.net/security_center/static/9415.php
CopyrightCopyright (C) 2002 Thomas Reinke

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.