VDB
CVE-2004-0488
CVE-2004-0488
PUBLISHED
CVSS 7.5 HIGH
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
EPSS 37.68% · 98.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
37.68%
98.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | http_server | 2.0.35 |
| n/a | n/a | n/a |
| redhat | enterprise_linux_server | 2.0 |
| debian | debian_linux | 3.0 |
| redhat | enterprise_linux_workstation | 2.0 |
Timeline
- Jul 18, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- May 3, 2022 CVE Updated
- May 5, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Apr 2, 2025 EPSS Score
- Apr 3, 2025 EPSS Score
- Apr 5, 2025 EPSS Score
- Apr 15, 2025 EPSS Score
- Apr 22, 2025 EPSS Score
References
- FLSA:1888 vendor-advisory
- [httpd-cvs] 20210330 svn commit: r1888194 [3/13] - /httpd/site/trunk/content/security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/ mailing-list
- GLSA-200406-05 vendor-advisory
- SSRT4777 vendor-advisory
- [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- [httpd-cvs] 20210330 svn commit: r1073139 [3/13] - in /websites/staging/httpd/trunk/content: ./ security/json/ mailing-list
- ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc technical
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021610.html advisory
- http://marc.info/?l=bugtraq&m=108567431823750&w=2 issue
- http://marc.info/?l=bugtraq&m=108619129727620&w=2 issue
- http://www.redhat.com/support/errata/RHSA-2004-342.html advisory
- http://www.securityfocus.com/bid/10355 patch
- http://www.trustix.net/errata/2004/0031/ technical
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E technical
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E technical
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E technical
- http://rhn.redhat.com/errata/RHSA-2004-245.html advisory
- http://www.debian.org/security/2004/dsa-532 advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:055 technical
…and 25 more