---
title: "CVE-2004-0885\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-0885?format=md
keywords: index, follow
---

# CVE-2004-0885

Publication date 3 November 2004

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The mod\_ssl module in Apache 2.0.35 through 2.0.52, when using the
"SSLCipherSuite" directive in directory or location context, allows remote
clients to bypass intended restrictions by using any cipher suite that is
allowed by the virtual host configuration.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| apache2 | 7.04 feisty | Fixed 2.2.3-3.2ubuntu0.1 |
| 6.10 edgy | Fixed 2.0.55-4ubuntu4.1 |
| 6.06 LTS dapper | Fixed 2.0.55-4ubuntu2.2 |
| libapache-mod-ssl | 7.04 feisty | Fixed 2.8.25-1 |
| 6.10 edgy | Fixed 2.8.25-1 |
| 6.06 LTS dapper | Fixed 2.8.25-1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0885)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-0885)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-0885)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-0885)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-0885>
