CVE-2005-1268

Apache HTTP Server 2.0.35-2.0.53 - Denial of Service via CRL Verification Buffer Overflow

Title source: llm
STIX 2.1

Description

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

References (31)

Core 31
Core References
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_18_sr.html
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_46_apache.html
Third Party Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm
Broken Link vendor-advisory x_refsource_trustix
http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/428138/100/0/threaded
Broken Link, Third Party Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:129
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19185
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/604
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19072
Patch, Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2005-582.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14366
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-805
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0789

Scores

EPSS 0.0839
EPSS Percentile 94.2%

Details

CWE
CWE-193
Status published
Products (8)
apache/http_server 2.0.35 - 2.0.54
debian/debian_linux 3.1
redhat/enterprise_linux_desktop 3.0
redhat/enterprise_linux_desktop 4.0
redhat/enterprise_linux_server 3.0
redhat/enterprise_linux_server 4.0
redhat/enterprise_linux_workstation 3.0
redhat/enterprise_linux_workstation 4.0
Published Aug 05, 2005
Tracked Since Feb 18, 2026