CVE-2005-3357
medium · 5.4mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
5.4
CVSS
24.3%
EPSS (exploit prob.)
98th
EPSS percentile
2005-12-31
Published
AV:N/AC:H/Au:N/C:N/I:N/A:C
Weaknesses
CWE-399
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | 2.0 |
| apache | http_server | 2.0.9 |
| apache | http_server | 2.0.28 |
| apache | http_server | 2.0.28 |
| apache | http_server | 2.0.32 |
| apache | http_server | 2.0.35 |
| apache | http_server | 2.0.36 |
| apache | http_server | 2.0.37 |
| apache | http_server | 2.0.38 |
| apache | http_server | 2.0.39 |
| apache | http_server | 2.0.40 |
| apache | http_server | 2.0.41 |
| apache | http_server | 2.0.42 |
| apache | http_server | 2.0.43 |
| apache | http_server | 2.0.44 |
| apache | http_server | 2.0.45 |
| apache | http_server | 2.0.46 |
| apache | http_server | 2.0.47 |
| apache | http_server | 2.0.48 |
| apache | http_server | 2.0.49 |
| apache | http_server | 2.0.50 |
| apache | http_server | 2.0.51 |
| apache | http_server | 2.0.52 |
| apache | http_server | 2.0.53 |
| apache | http_server | 2.0.54 |
| apache | http_server | 2.0.55 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37791
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://rhn.redhat.com/errata/RHSA-2006-0159.html
- http://secunia.com/advisories/18307
- http://secunia.com/advisories/18333
- http://secunia.com/advisories/18339
- http://secunia.com/advisories/18340
- http://secunia.com/advisories/18429
- http://secunia.com/advisories/18517
- http://secunia.com/advisories/18585
- http://secunia.com/advisories/18743
- http://secunia.com/advisories/19012
- http://secunia.com/advisories/21848
- http://secunia.com/advisories/22233
- http://secunia.com/advisories/22368
- http://secunia.com/advisories/22523
- http://secunia.com/advisories/22669
- http://secunia.com/advisories/22992
- http://secunia.com/advisories/23260
- http://secunia.com/advisories/29849
- http://secunia.com/advisories/30430
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-3357