Description
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
References (31)
... and 11 more
Scores
EPSS
0.0427
EPSS Percentile
88.9%
Details
CWE
CWE-193
Status
published
Products (8)
apache/http_server
2.0.35 - 2.0.54
debian/debian_linux
3.1
redhat/enterprise_linux_desktop
3.0
redhat/enterprise_linux_desktop
4.0
redhat/enterprise_linux_server
3.0
redhat/enterprise_linux_server
4.0
redhat/enterprise_linux_workstation
3.0
redhat/enterprise_linux_workstation
4.0
Published
Aug 05, 2005
Tracked Since
Feb 18, 2026