VDB

RHSA-2004%3A408

RHSA-2004%3A408 PUBLISHED CVSS 9.300000190734863 CRITICAL

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux AS (Advanced Server) version 2.1
Red HatRed Hat Enterprise Linux ES version 2.1
Red HatRed Hat Linux Advanced Workstation 2.1
Red HatRed Hat Enterprise Linux WS version 2.1

Timeline

  • Sep 7, 2004 CVE Published
  • Nov 21, 2025 CVE Updated
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›