CVE-2005-3357

Publication date 31 December 2005

Last updated 24 July 2024


Ubuntu priority

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.

Status

Package Ubuntu Release Status
apache2 7.04 feisty
Fixed 2.2.3-3.2ubuntu0.1
6.10 edgy
Fixed 2.0.55-4ubuntu4.1
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.2

References

Related Ubuntu Security Notices (USN)

    • USN-241-1
    • Apache vulnerabilities
    • 13 January 2006

Other references